Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Request-ID
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
Permissions-Policy
X-Turbo-Charged-By
X-Proxy-Cache
Xkey
X-Ws-Request-Id
X-Rq
X-Age
X-Vhost
X-Amz-Version-Id
X-Dispatcher
Cf-Apo-Via
X-Dns-Prefetch-Control
Allow
X-Swift-CacheTime
X-Swift-SaveTime
X-LiteSpeed-Cache
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-Host
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Node
Content-Location
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
P3p
X-NWS-LOG-UUID
X-Country
Service-Worker-Allowed
X-Country-Code
X-CST
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
Rating
X-Litespeed-Cache
X-Rack-Cache
X-Url
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
X-Times
X-TtlSet
X-Vname
X-PC
Nginx-Cache
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Oneagent-Js-Injection
X-Server-Name
X-Edge
X-Mcache
X-Browser-Type
X-Midtier
X-Webkit-Csp
X-Powered-By-Plesk
X-ESI
X-Cnection
X-ECACHE
X-GitHub-Request-Id
Edge-Control
X-D2id
X-Element-Page-Cache
X-Upstream
Verso
AR-Request-ID
X-Ac
AR-PoweredBy
AR-ATIME
X-MS-InvokeApp
AR-SID
X-Exp-Id
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-FastCGI-Cache
X-B3-TraceId
X-Cache-TTL
X-Vcap-Request-Id
Accept-Ch-Lifetime
X-Ser
X-Abt-Application-Version
X-Navigation-Version
AR-CACHE
X-Dw-Request-Base-Id
SPIisLatency
SPRequestDuration
X-Mod-Pagespeed
SPRequestGuid
X-SharePointHealthScore
X-NF-Request-ID
Fastly-Restarts
X-Amz-Rid
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
Pagespeed
X-Aws-Lambda-Call-Status
X-Sol
Display
X-Middleton-Display
X-Mg-S
Edge-Cache-Tag
X-Kinsta-Cache
X-Edge-Location-Klb
X-Client-IP
S
X-Ruxit-Js-Agent
X-Powered-CMS
X-Goog-Hash
X-Middleton-Response
Response
X-Version
Cache-Status
Access-Control-Request-Method
X-VARITI-CCR
X-Amzn-Trace-Id
X-Fastly-Request-ID
X-ARC
X-Cache-Key
RTSS
X-Ratelimit-Limit
X-Content-Digest
X-TraceId
Cross-Origin-Resource-Policy
X-Forwarded-For
X-T
X-Recruiting
Realpath
X-Varnish-TTL
X-PDP-UNCACHING-HASH
X-RateLimit-Remaining
X-Ratelimit-Remaining
X-Correlation-Id
X-TTL
Front-End-Https
X-MSEdge-Ref
Fastcgi-Cache
X-Cached
MS-Author-Via
Content-MD5
X-Ua-Browser
X-HS-Hub-Id
X-HS-Content-Id
X-Shield-Request-Id
X-HS-Cache-Config
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
MicrosoftSharePointTeamServices
X-Request-Received
X-Protected-By
X-Request-Processing-Time
Server-Node
Payment
Public-Key-Pins
X-LLID
TP-Cache
X-HS-Combine-CSS
X-Frontend
X-Forwarded-Proto
X-Pinterest-Rid
Pinterest-Generated-By
Arr-Disable-Session-Affinity
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Pinterest-Version
X-FTR-Expires
X-Distributor
X-HP-Trace-Id
X-Jurisdiction
X-Accel-Expires
X-HP-Webp
X-ORACLE-DMS-RID
Count-Hit
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-GUploader-UploadID
X-Origin-Server
X-Server-ID
X-LB-Cache
X-NODE
X-Ezoic-Cdn
X-Microsite
X-Request-Handler-Origin-Region
X-Ttl
X-PressLabs-Stats
X-Content-Security-Policy-Report-Only
X-Activity-Id
X-AppVersion
X-Az
Host
X-Varnish-Backend
MRF-Tech
X-Cluster-Name
Mrf-Cache-Status
X-TEC-API-ORIGIN
X-Varnish-Server
X-Www-Served-By
X-TEC-API-VERSION
X-TEC-API-ROOT
X-B3-TraceId-Primal
Cache-Tags
X-App-Server
Accept-Charset
Retry-After
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-Ua-Device
X-Newrelic-App-Data
Cleartype
X-Hostname
X-CSRF-Token
X-Goog-Metageneration
X-Envoy-Decorator-Operation
X-Geo-Country
X-ORACLE-DMS-ECID
X-Hits
X-Origin-Cache-Key
X-NGENIX-Cache
Referer-Policy
X-Git-Hash
X-Upgrade-Enabled
TP-L2-Cache
Filterid
X-Unique-Id
X-DIS-Request-ID
X-Seen-By
X-Azure-Ref
Access-Control-Allow-Method
TCN
X-Load-Cache
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Tt-Trace-Host
X-Hcs-Proxy-Type
X-Tt-Trace-Tag
X-Proxy
X-F-Cache
X-Revision
Section-Io-Cache
X-Trace-Id
X-Grace
X-Request-Guid
X-B3-Sampled
Healthy
X-Cache-Control
X-B
DC
X-Logged-In
X-Type
X-TT
X-Contextid
X-Amz-Apigw-Id
X-Amzn-RequestId
Paypal-Debug-Id
X-FB-Debug
X-Fb-Rlafr
X-Debug
X-Debug-Info
X-Id
X-Px
X-Page-Id
X-N
X-Mobile
Viewport
X-Oracle-Dms-Ecid
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
Fastly-SIE
Fastly-SWR
X-Goog-Stored-Content-Encoding
X-Whom
X-XRDS-LOCATION
X-Varnish-Ttl
X-Oracle-Dms-Rid
Content-Disposition
X-Via-JSL
Charset
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Content-Options
Version
X-Time
X-Varnish-Grace
X-Template
X-Origin-Cache
X-Webkit-CSP
X-Wix-Request-Id
X-Magnolia-Registration
X-Cache-Grace
Surrogate-Key
X-App-Environment
X-Rid
X-RateLimit-Limit
X-Signature
X-B3-SpanId
X-B-Cache
X-ProcessESI
VIX-Pulpo-Upstream-Status
X-RemovedCookies
VIX-Pulpo-Node
SRV
X-Tumblr-User
X-Debug-IsConnected
X-Debug-IsPreview
X-Amz-Replication-Status
X-Rule
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Node-Name
X-EdgeConnect-Cache-Status
X-G
X-Datadog-Sampled
Ms-Operation-Id
X-Hl-Ver
X-RTag
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-UUID
MS-CV
SD-X-WS
X-FW-Dynamic
X-Adobe-Content
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
X-Adobe-Loc
X-FW-Version
X-Instance
X-Backend-Name
X-Language
X-Storage
ServerID
X-FW-Type
NGB
X-Cacheable-TTL
X-Device-Type
GEO-INFO
X-Rendered-As
X-NYM-Debug-Backend
X-Is-Bot
X-Region
X-Environment-Context
X-Status
X-Cache-Hit
X-User-Agent
X-Amzn-Remapped-Content-Length
X-Proxy-Cache-Info
X-L-Path
Country
X-IPS-LoggedIn
Countrycode
Liferay-Portal
X-Real-IP
X-Source
X-NWS-UUID-VERIFY
X-ServerID
X-URL
Akamai-GRN
X-WP-CF-Super-Cache-Active
Cross-Origin-Window-Policy
X-Sucuri-ID
X-RateLimit-Reset
X-Sucuri-Cache
Amp-Access-Control-Allow-Source-Origin
OT-Force-Account-Verify
X-Cache-Age
X-Servername
X-UA
X-RM-Cache-TTL
X-VC-Cache
From-Origin
Front
X-WebKit-CSP-Report-Only
X-Framework
X-Air-Pt
X-Wormhole-Sdk
Upgrade-Insecure-Requests
Backend
X-INCAP-ABP
X-Mode
X-AB
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Akamai-Request-ID2
X-Content-Powered-By
Xet-Cookie
X-Cache-Time
Refresh
X-Xrds-Location
X-Handled-By
X-DataDome
X-Nginx-Cache
X-Edge-Location
Accept-Language
X-Endurance-Cache-Level
X-SaId
X-Origin-CC
X-Rn-Rsrv
X-UPSTREAM-Address
X-RCS-CacheZone
X-HTML-Minification-Powered-By
X-Rewrite-Enabled
X-SRV
X-Origin-TTL
Filters
X-JoinUs
Frame-Options
X-Xfnlog-Site
Meta-Geo
Url
X-Reqid
X-LJ-Flow-ID
Webcakes-Region
Webcakes-App-Version
X-Origin-Hint
X-Origin-Date
X-No-Session
Cache
Property-Id
ServedBy
TWC-Connection-Speed
X-Cache-Operation
X-Cache-Rule
X-Git-Commit
X-Akamai-Edgescape
TWC-GeoIP-LatLong
X-Provided-By
X-VWS-Id
TWC-Privacy
TWC-Locale-Group
X-Webstats-RespID
X-Cluster
X-CDN-Forward
Webcakes-App-Name
TWC-GeoIP-Country
X-AWS-Id
X-PHP-Host
X-Labrador-Cache-Channel
X-Vcache
X-Tumblr-Pixel-2
TWC-Device-Class
X-Container-Uri
WPO-Cache-Status
X-Cache-Debug
X-IPLB-Request-ID
X-Proxied
Web-Mar-Node
X-Varnish-Cache-Hits
X-Web-Node
X-Extlb
X-R9-Blue-Green-Version
X-Redis-Cache
X-Routing-Service
X-Scope-Id
X-Served-From
X-Accel-Version
X-Fetched-On
WPO-Cache-Message
X-IPLB-Instance
X-Cms-Context
X-Cloudmap
X-Adobe-Source
Cache-Hits
X-Restarts
X-Hosted-By
X-Zipkin-Id
Section-Io-Id
Mn-Server-Ip
X-Logging-Id
Atl-Traceid
X-Ratelimit-Reset
X-XRDS-Location
Webserver
X-Tncms
X-Timing-Wait
X-Lambda-Id
X-Upstream-Ht
X-Ms-Request-Id
X-Loop
Access-Control-Request-Headers
Apigw-Requestid
X-Site-Version
X-Forwarded-Host
X-Format
X-Upstream-Ct
X-Frame-Option
X-Drupal-Cache-Tags
X-Varnish-Age
X-Director
X-BYPASS-REASON
X-Ms-Version
X-VCT
X-Skip-Cache
Selected-Fe
X-Locale
X-Say-Cacheable
X-Azure-Ref-OriginShield
X-ProxyCache-Status
X-SayCDN-TTL
X-Tb
X-Soup
X-Proxy-Build
X-ProxyCache-Key
X-Say-TTL
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Drupal-Cache-Contexts
Xserver
X-Varnish-Beresp-Grace
X-Browser-Name
X-Cache-Host
X-Shopify-Stage
X-CMSURLCustom
X-Detected-As
X-Is-Supported-Browser
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Origin
X-Sorting-Hat-PodId
X-S
X-ShopId
X-Shield-Cache-Expires
X-ShardId
X-Tcp-Rtt
X-Thinkindot-L3
X-GeoCountry
X-GeoCode
X-Geo-Region
X-Httpd
X-Is-Desktop
X-Is-Tablet
Thinkindot-CacheControl
X-Is-Mobile
X-Generation-Time
X-Alternate-Cache-Key
X-Generated-By
TDXMobile
X-Cache-Status-Check
X-VC
X-Cdn-Origin
X-Buckets
LB
X-RID
X-Lagoon
X-Optimistic-Header
X-Worker
X-Rocket-Nginx-Serving-Static
Fastcgi-Useragent
Source
X-Request-URI
X-WP-CF-Super-Cache-Cookies-Bypass
X-Vercel-Id
X-Vercel-Cache
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
X-ID
Azure-InstanceId
Protected
Node
Onion-Location
X-Connection-Hash
X-Vcl-Version
Expiry
X-Pass-Why
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-RequestPullSuccess
CDN-Cache
CDN-CachedAt
CDN-RequestPullCode
CDN-Uid
X-TA-CDN-Provider
X-Api-Version
X-GEO
Cross-Origin-Embedder-Policy
X-App-Version
X-Cache-Expired-At
X-Tumblr-Pixel-3
X-Tec-Api-Root
X-Client-Ip
X-Tec-Api-Version
X-Tec-Api-Origin
Alternate-Protocol
X-PHP-Backend
Environment
X-Cache-Server
X-Ismobilevalue
X-Server-W
AMP-Access-Control-Allow-Source-Origin
Cdn-Requestid
X-Proxy-Cache-Status
Uber-Trace-Id
X-Tt-Logid
Priority
CF-IPCountry
X-Jobs
DB-Nickname
X-Cluster-Node
X-Cache-Action
Locale
X-DC
X-Urbn-Context-Path
X-Fastly-Request-Id
CDN-RequestId
X-Urbn-Site-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
User-Cache-Control
X-Mg-Request-UUID
X-Fastcgi-Cache
Sid
X-B3-Traceid
X-Tx-Id
X-LSADC-Cache
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
Cache-Tv-Group
X-MP-GENERATED-AT
Fusion-Deployment-Id
Fusion-Component-Id
DCR-Decision-By
A
X-Auth-Group-Type
Candidate-Md5Url
Content-Secure-Policy
Gannett-Cam-Experience-Id
Magicmarker
MD5-Digest
Lang
Meta-Geo-Continent
Edge-Cache
DCR-Processing-Time-Ms
X-A-Wwc
X-Jungle-Id
X-Ig-Push-State
X-Level-Front-Cache
X-NCache
X-Op-Id-All
X-ND-Cache
X-Ig-Origin-Region
X-Hnp-Log
X-Esi-Check
X-Epic-Correlation-Id
X-FB-TRIP-ID
X-Gen-Mode
X-Gzip
X-Generated-On
X-Org
X-Origin-Expires
X-Vdms-Version
X-Varnish-Hostname
X-Viewer-Country
X-VTEX-Cache-Server
X-Vtex-Remote-Cache
X-VTEX-Cache-Time
X-UA-Device-Type
X-TIM-N
X-Rojux
X-Powered-By-VTEX-Cache
X-SB
X-ScT
X-SRCache-Key
X-Ec-GeoHdr
X-Ec-Fail
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-A
X-A-Dam
X-A-Ccd
Vix-Hermes-Req-Id
T-Server
Origin-Agent-Cluster
Origin
Server-Host
Sslversion
Surrogated-Key
X-A-Dcw
X-A-Dgt
X-Content-Age
X-Conf
X-D
X-Developer
X-Dispatcher-Server
X-Device-Os
X-Cache-NE
X-Cache-Id
X-Bc-Bl
X-Aed
X-BCube-Filmed-By
X-Bl-Debug
X-Block-Status
Ngx.Var.Host
Rendered-Blocks
X-Varnish-Beresp-Ttl
HostName
X-Nf-Request-Id
X-Origin-Response-Time
X-VG-WebCache
X-Req
X-Cache-Info
Host-ID
X-Cache-Bucket
X-Request-Start
X-Request-Time
X-Bip
X-Cache-TTL-Remaining
X-Via-Fastly
X-Cdn-Srv
X-Proto
X-Pubstack
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Fastly-Backend-Name
X-RateLimit-Limit-Second
X-Vdms-Path
X-Clientip
X-RateLimit-Remaining-Second
Fastly-SSL
Content-Style-Type
NM-Fastcgi-Cache
X-Tb-Optimization-Total-Bytes-Saved
Server-Ext
Req-ID
X-AK-Request-ID
Server-Hostname
Sever-Int
X-Thanos
X-Mvc-Supplant-Cachable
X-Test
X-V-Cache
X-Amz-Storage-Class
Powered-By
X-Auto-Login
X-VarnishDD-TTL
Content-Script-Type
X-Scheme
X-SD-PageType
X-Varnish-Director
X-App-Name
PFcat
Origin-EX
Origin-CC
X-Backend-Instance
X-Core-Value
X-Origin-Time
X-Gdpr
X-Nyt-Route
X-Geo-Header
X-Forwarded-Site
AKAMAI
X-Fastly-Cache
X-PAYTM-SRV-ID
X-FC-Vary-Parameters
X-Fmm-Version
X-GeoIP
X-GeoIP-City
X-NMSegId
X-Service
X-Nginx-Cache-Key
X-Loc
X-Node-Id
X-HS-Content-Campaign-Id
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-HN
C-Via
Odigeo-Trace-Id
Cdn-Host
XM
Cdn-Request-Time
Cdncip
X-Policy
Cdnsip
CDCHOST
X-Edge-Server
Cache-Provider
X-Platform
X-SVT-ORM-VERSION
X-Ec-Custom-Error
X-Mvc-Supplant-OutputCached
X-Pool
X-SVT-ORM-RULES
X-Cache-Backend
X-Access
X-Sn-Servicetimems
X-Response-Served-From
X-HITS
Web-Mar-Region
V-Age
X-Micro-Cache
X-Mly-Id
X-Men
X-Location
X-Acquia-Purge-Cdn-Unconfigured
We-Hiring
W
X-DPWN-IS-SECURE
X-Newrelic-Synthetics
X-Eu-Site
Tube-Return
X-Csrf-Jwt
X-Original-Request-Id
X-CGP
X-Contensis-Viewer-Groups
X-From
X-B3-Trace-ID
X-Cache-Aspx
X-GoCache-CacheStatus
X-Proxied-Request
X-Aicache-OS
X-BBC-Edge-Cache-Status
X-Human
X-Fastly-Backend
X-CUA
X-NodeID
X-Section
X-Ad-Load-Variation
Tube-Get-Contents
Tube-Got-Results
X-Uri
Gh-Request-Id
Esi-Enabled
DSUID
Country-Code
X-WA-Info
Ha-Gx-Prefs
HA-Ipaddr
Machine
Mail-Subject
X-ECache
L5d-Success-Class
Is-Eu
L
X-We-Are-Hiring
Cluster
Adler-Geo
Apple-News-Services-Handled
Apple-News-Services-Host
Yak-Timeinfo
X-Zone
X-Custom-Header
X-Region-Sid
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Click-Count-Action-Start
Click-Count-Error
X-Wikidot-Backend
X-Wikidot-Static-Cache
Cache-Key
Canary
X-VG-TLSProxy
Fastly-GeoIP-CountryCode
X-Varnish-Beresp-Status
Req-Svc-Chain
Release
Redirect-Candidate
Producers
X-Varnish-Authentication
RNT-Time
Tube-Got-Eval
True-Client-Country-4JS
Ssr
X-Var-Ttl
Pramga
RNT-Machine
Platform
X-Varnishpool
On-Server
X-Date
X-Up
Proxy-Firewall
X-Accel-Expires-Debug
X-LiteSpeed-Cache-Control
X-Hash
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Server-IP
X-Request-Host
NGX
X-CacheTTL
WP-Super-Cache
X-AIR-PT
X-TT-LOGID
X-ApacheServer
X-Varnish-CookieINHashed-On
X-Varnish-Hits
SID
X-Varnish-CookieHashed-On
X-PERF
X-DefHash
X-CACHE-AGE
X-DefElseHash
Debug
X-NGINX-Cache
X-Render-Time
X-Varnish-Remaining-TTL
Fastly-Drupal-HTML
Mime-Version
X-Pad
X-LB-ID
X-COUNTRY
X-Nananana
X-Depends
X-Dc
X-Refresh
X-CACHE-GROUP
CloudFront-Viewer-Country
X-HA-Backend
X-Via-Popn
X-Cs
Pics-Label
X-Via-Popv
X-Via-Poph
X-Parent-Response-Time
X-Cache-FS-Status
X-Servedbyhost
X-Akamai-Transformed
Datacenter
X-VHOST
X-TIME
Locid
GeoIP-Latitude
X-LB-NoCache
X-M-Reqid
X-M-Log
X-Amz-Meta-Cb-Modifiedtime
X-VC-TTL
X-Datadome
X-Platform-Router
X-CS
X-Cached-By
X-Platform-Processor
X-B3-Parentspanid
X-Platform-Cluster
Server-Info
BehaviorPad-Version
Server-ID
X-Old-Content-Length
Ngx-Var-Key
X-Litespeed-Tag
Cdn
X-APP
X-LiteSpeed-Tag
X-Wa
Resin-Trace
X-CDN-Cache-Status
X-Nc
X-DynaTrace-JS-Agent
Fastly-Drupal-Html
Cf-Ipcountry
X-Presslabs-Stats
GeoIp-Country-Code
X-Vc
X-TH-Server
X-Moov-Xdn-Version
X-Moov-T
X-Vgn-Hpd-Reason
X-Content-Length
X-Fpc
X-VCache
Cross-Origin-Embedder-Policy-Report-Only
X-IAuth-Set-Uid
NtCoent-Length
Uri
X-NewRelic-App-Data
FSS-Cache
X-ZONE
X-B-Cookie
X-User
True-Client-IP
X-S-Cookie
Cf-Device-Type
X-Application
X-Destination
X-Esi
X-External-Request-Id
Serverhost
True-Client-Ip
X-Dynatrace-Js-Agent
X-HostName
CDN
X-TX-ID
X-SERVER-NAME
X-Varnish-Beresp-TTL
X-Srv
X-Dispatcher-Number
X-Zen-Fury
Vc-Max-Age
X-Rocket-Build-Number
X-Sigma
Tcn
X-Cache-Date
X-RequestId
S-Rt
GeoIP-Country-Code
X-Sigma-Backend
X-Instance-Name
X-Oracle-DMS-ECID
X-HOST
X-API-Version
Srv
X-Cdn-Cache-Status
Product
X-VServer
Request-ID
Load-Balancing
X-WA
X-FPC
X-Dispatch
X-NC
X-Branch-Name
X-Segment-20210421
X-DynaTrace
Hostname
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Cdn-Forward
X-Aspnet-Duration-Ms
X-CACHE-KEY
X-Route-Name
X-Ckpd-Fst-Backend
Ohc-File-Size
X-B3-Spanid
X-APP-VERSION
Server-Id
X-Bug-Bounty
ServerName
X-DataCenter
Geoip-Latitude
Srvid
X-FL-QIT-DEBUG
X-Webkit-Csp-Report-Only
X-Page-View
X-Geo
X-Lb-Nocache
Type
CacheControlHeader
Origin-Trial
DataCenter
X-ServedByHost
X-Irp-Debug
X-Nf-Language
X-Http-Reason
X-VCL-Version
X-Nf-Country
X-Sql-Duration-Ms
X-Sql-Count
X-Nf-Ats-Version
X-HubSpot-Correlation-Id
Epwk-X-Cache
Cloudfront-Viewer-Country
Cl-Cache
X-Cache-Ttl
X-Via-SSL
PICS-Label
Edge-Copy-Time
X-Correlation-ID
Cneonction
X-Akamai-Device-Characteristics
X-Via-PopH
X-App
X-Via-PopN
X-Via-PopV
User-Agent
IsBot
X-Via-Edge
X-SIPLIST1
X-Owner
X-Via-CDN
Ohc-Cache-HIT
X-Vmg-Version
X-Ua
Cross-Origin-Opener-Policy-Report-Only
X-Ha-Backend
X-Srcache-Store-Status
Rtss
X-Srcache-Fetch-Status
ServerHost
X-Info
Cmstype
Cmsid
X-Lb-Id
X-Gamma-Serve
X-MiniProfiler-Ids
XkeyRZ
MIME-Version
X-Proxy-CacheRZ
X-Core-Mission
WZWS-RAY
Lb
X-Service-Response-Time
Warning
X-Sqd-Ctime
Sm-Log-Id
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Web-Server
N-Cache
X-Datacenter
X-Limited
X-Fastly-Country-Code
Xc-Version
X-MSEdge-Flight
X-MSEdge-Features
X-Acquia-Application-Trace
X-Qloud-Router
X-Sqd-Stime
CountryCode
Servername
X-Hit
X-Litespeed-Cache-Control
X-LAGOON
X-Snapshot-Date
Ngx
X-Ramcache
X-Serial
X-Akamai-Pragma-Client-IP
X-Check-Cacheable
X-Th-Server
X-Requestid
X-RAMCache
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Sha256
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-Amz-Meta-Opti
X-IN-APIGATEWAYSSL
X-Udemy-Cache-App-Namespace