Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Accept-CH
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Check
X-Drupal-Cache
X-Ua-Compatible
X-Generator
X-Cache-Status
Server-Timing
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Permissions-Policy
Host-Header
X-Via
EagleId
Keep-Alive
Request-Context
X-Cache-Group
X-Robots-Tag
X-Backend
X-UA-Device
X-AH-Environment
X-Hacker
X-Proxy-Cache
X-Server
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
Xkey
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Server-Powered-By
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
Allow
X-Varnish-Cache
P3p
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-WebKit-CSP
X-Host
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Backend-Server
Cf-Railgun
X-Dns-Prefetch-Control
X-Server-Id
X-Readtime
X-Response-Time
Surrogate-Control
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-HW
X-Node
Request-Id
X-Cloud-Trace-Context
X-Country
Content-Location
X-Nginx-Cache-Status
X-Application-Context
Accept-Ch-Lifetime
X-Nginx-Upstream-Cache-Status
X-Litespeed-Cache
X-ASPNET-VERSION
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
Cache-Tag
X-Clacks-Overhead
Rating
X-Amz-Server-Side-Encryption
X-Times
X-Rack-Cache
X-PC
X-TtlSet
X-Vname
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Server-Name
X-Daa-Tunnel
Nginx-Cache
Accept-Ch
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
X-Powered-By-Plesk
X-Cache-TTL
X-Cnection
X-FTR-Request-ID
X-ESI
X-Ac
X-D2id
X-GitHub-Request-Id
X-Element-Page-Cache
Verso
Edge-Control
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Server
X-CST
X-MS-InvokeApp
AR-CACHE
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Upstream
X-Navigation-Version
Fastly-Restarts
X-Webkit-Csp
X-B3-TraceId
X-ECACHE
SPIisLatency
SPRequestDuration
X-FastCGI-Cache
X-Mod-Pagespeed
X-Amz-Rid
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Client-IP
X-SharePointHealthScore
SPRequestGuid
X-ARC
X-Goog-Hash
X-Edge-Location-Klb
X-Kinsta-Cache
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Oneagent-Js-Injection
X-Powered-CMS
X-Mg-S
X-Ratelimit-Limit
X-Amzn-Trace-Id
Edge-Cache-Tag
S
Cache-Status
X-Version
Access-Control-Request-Method
X-Middleton-Response
Response
X-VARITI-CCR
X-Ratelimit-Remaining
X-NF-Request-ID
RTSS
Realpath
X-Forwarded-For
X-Cache-Key
X-T
Cross-Origin-Resource-Policy
X-Content-Digest
X-Server-ID
X-TTL
Fastcgi-Cache
X-Cached
X-Correlation-Id
X-Recruiting
X-ORACLE-DMS-RID
X-Fastly-Request-ID
X-MSEdge-Ref
X-Shield-Request-Id
X-TraceId
MicrosoftSharePointTeamServices
Front-End-Https
X-Forwarded-Proto
X-PressLabs-Stats
X-Ua-Browser
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ruxit-Js-Agent
X-Frontend
Payment
TP-Cache
X-Request-Received
X-Request-Processing-Time
X-HS-Cache-Config
X-LLID
Arr-Disable-Session-Affinity
X-HS-Hub-Id
X-HS-Content-Id
Server-Node
Public-Key-Pins
X-Protected-By
Count-Hit
X-Newrelic-App-Data
Content-MD5
X-GUploader-UploadID
X-Accel-Expires
X-HS-Combine-CSS
X-LB-Cache
X-RateLimit-Remaining
MS-Author-Via
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Varnish-TTL
X-Distributor
X-TEC-API-ROOT
X-Origin-Server
X-NODE
Surrogate-Key
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ezoic-Cdn
X-ORACLE-DMS-ECID
X-Microsite
X-Request-Handler-Origin-Region
X-HP-Webp
X-FTR-Balancer
X-Content-Security-Policy-Report-Only
X-FTR-Cache-Status
X-HP-Trace-Id
X-FTR-Backend
X-Country-Code-Real
X-Jurisdiction
X-FTR-Backend-Server
X-Www-Served-By
Accept-Charset
Host
Mrf-Cache-Status
X-Varnish-Server
X-Activity-Id
X-App-Server
X-Az
MRF-Tech
X-AppVersion
X-B3-TraceId-Primal
Cleartype
X-Ua-Device
X-Cluster-Name
Cache-Tags
X-Varnish-Backend
X-Amz-Meta-S3cmd-Attrs
Retry-After
X-Ttl
X-Goog-Metageneration
Filterid
X-Unique-Id
X-FTR-Expires
X-Debug
Server-Name
X-Git-Hash
Access-Control-Allow-Method
X-Aspnet-Version
X-Logged-In
X-Varnish-Ttl
X-Hits
X-Load-Cache
X-Upgrade-Enabled
X-Id
X-Azure-Ref
X-Envoy-Decorator-Operation
X-NGENIX-Cache
X-FB-Debug
X-CSRF-Token
X-Geo-Country
X-Amz-Apigw-Id
TCN
X-Amzn-RequestId
X-Hostname
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-B
X-Seen-By
X-TT
Section-Io-Cache
TP-L2-Cache
X-Proxy
X-Request-Guid
X-Cache-Control
Viewport
Healthy
X-Revision
X-Type
X-Grace
X-Fb-Rlafr
X-Trace-Id
X-Contextid
X-B3-Sampled
DC
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Fastly-SIE
X-F-Cache
Fastly-SWR
X-Time
X-Hcs-Proxy-Type
X-N
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Ratelimit-Reset
Content-Disposition
X-Mobile
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Referer-Policy
Paypal-Debug-Id
X-Nf-Request-Id
X-Varnish-Grace
X-Amz-Replication-Status
X-XRDS-LOCATION
X-Magnolia-Registration
X-Origin-Cache
X-Webkit-CSP
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Via-JSL
X-DIS-Request-ID
X-Wormhole-Sdk
X-Debug-Info
X-Page-Id
Version
X-Oracle-Dms-Ecid
X-Px
X-Ismobilevalue
X-Rid
X-UUID
Amp-Access-Control-Allow-Source-Origin
X-Datadog-Sampling-Priority
X-Content-Options
X-G
X-ProcessESI
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-RemovedCookies
X-Tumblr-Pixel-1
X-Adobe-Content
X-Tumblr-Pixel-0
X-Tumblr-User
X-Source
X-Rule
X-Adobe-Loc
X-Tumblr-Pixel
X-App-Environment
SD-X-WS
Ms-Operation-Id
NGB
X-Whom
X-NYM-Debug-Backend
X-Node-Name
X-Instance
X-Region
X-RTag
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Wix-Request-Id
X-Hl-Ver
Cross-Origin-Window-Policy
X-Datadog-Sampled
X-Template
VIX-Pulpo-Upstream-Status
X-Debug-IsConnected
X-Debug-IsPreview
VIX-Pulpo-Node
MS-CV
GEO-INFO
X-Device-Type
X-Rendered-As
X-B-Cache
X-Is-Bot
X-Proxy-Cache-Info
X-Signature
X-Status
X-Cacheable-TTL
X-Backend-Name
X-User-Agent
X-Storage
X-ServerID
X-L-Path
X-FW-Version
X-FW-Dynamic
X-Environment-Context
X-FW-Hash
X-FW-Serve
X-FW-Type
X-FW-Static
Country
X-FW-Server
X-Cache-Age
Charset
X-RM-Cache-TTL
Countrycode
Akamai-GRN
Front
SRV
ServerID
X-IPS-LoggedIn
X-NWS-UUID-VERIFY
X-Framework
X-WP-CF-Super-Cache-Active
X-Real-IP
X-EdgeConnect-Cache-Status
X-Cache-Grace
X-ECache
X-AB
Liferay-Portal
X-Amzn-Remapped-Content-Length
X-Cache-Hit
X-Language
X-B3-SpanId
X-Oracle-Dms-Rid
X-Air-Pt
X-Content-Powered-By
X-Api-Version
X-Akamai-Request-ID2
X-Fastly-Request-Id
X-DataDome
X-WebKit-CSP-Report-Only
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-VC
OT-Force-Account-Verify
X-Servername
Xet-Cookie
X-UA
X-Sucuri-ID
X-Sucuri-Cache
Accept-Language
X-URL
X-VC-Cache
From-Origin
X-Mode
X-Xrds-Location
LB
X-SRV
Backend
Access-Control-Request-Headers
X-Cache-Status-Check
Refresh
X-Tt-Logid
X-HTML-Minification-Powered-By
X-Nginx-Cache
X-Mg-Request-UUID
Upgrade-Insecure-Requests
X-Handled-By
Webserver
Meta-Geo
X-Rn-Rsrv
Filters
X-Rewrite-Enabled
X-Cache-Time
X-SaId
X-JoinUs
X-Git-Commit
X-RCS-CacheZone
X-Container-Uri
X-UPSTREAM-Address
X-Origin-Date
TWC-Connection-Speed
X-Webstats-RespID
Webcakes-App-Version
TWC-Locale-Group
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
Webcakes-App-Name
X-Adobe-Source
X-S
X-Provided-By
Webcakes-Region
Xserver
Property-Id
X-Hosted-By
X-Generated-By
X-Request-URI
X-Forwarded-Host
X-RateLimit-Limit
X-R9-Blue-Green-Version
X-Varnish-Age
X-Labrador-Cache-Channel
X-Origin-Hint
X-PHP-Host
X-Tumblr-Pixel-2
X-Cms-Context
Mn-Server-Ip
Url
X-Scope-Id
X-Redis-Cache
X-Served-From
X-Reqid
X-Lambda-Id
X-Locale
X-Loop
X-Logging-Id
X-ProxyCache-Key
X-No-Session
X-Tncms
X-Tcp-Rtt
X-Tb
X-Vcl-Version
X-ProxyCache-Status
Apigw-Requestid
X-Storefront-Renderer-Rendered
Atl-Traceid
Cache
X-Site-Version
X-Browser-Name
Section-Io-Id
X-Alternate-Cache-Key
X-Fetched-On
X-BYPASS-REASON
X-Cache-Debug
X-Web-Node
X-Cache-Host
ServedBy
X-Shopify-Stage
Web-Mar-Node
X-Format
X-Is-Desktop
X-Skip-Cache
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Tablet
X-Akamai-Edgescape
X-Restarts
X-Xfnlog-Site
X-Geo-Region
X-Accel-Version
X-Httpd
Selected-Fe
X-Proxy-Build
X-Cluster
X-Upstream-Ht
X-Varnish-Beresp-Grace
X-Varnish-Cache-Hits
X-VCT
X-Upstream-Ct
X-Soup
X-Origin
X-Optimistic-Header
X-Timing-Wait
X-IPLB-Request-ID
X-IPLB-Instance
Onion-Location
X-Say-TTL
X-Detected-As
X-Director
X-Frame-Option
X-Say-Cacheable
X-SayCDN-TTL
X-Cloudmap
X-Extlb
X-LJ-Flow-ID
X-AWS-Id
X-ShardId
X-Cache-Rule
X-Vcache
X-Routing-Service
X-Cache-Operation
X-Zipkin-Id
X-VWS-Id
X-Proxied
X-ShopId
X-RID
X-Edge-Location
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Ms-Request-Id
X-Cache-Expired-At
X-Ms-Version
X-Endurance-Cache-Level
X-INCAP-ABP
X-CDN-Forward
X-Aws-Lambda-Call-Status
Expiry
X-Lagoon
X-Connection-Hash
Cdn-Requestid
Source
WPO-Cache-Status
X-GeoCountry
X-GeoCode
X-WP-CF-Super-Cache-Cookies-Bypass
Frame-Options
WPO-Cache-Message
X-Azure-Ref-OriginShield
Priority
Environment
X-XRDS-Location
X-Fastcgi-Cache
Protected
X-Proxy-Cache-Status
X-Cache-Action
CF-IPCountry
X-Generation-Time
TDXMobile
Thinkindot-CacheControl
X-Shield-Cache-Expires
Thinkindot-Control
Thinkindot-CacheControl-Type
X-CMSURLCustom
X-Thinkindot-L3
Fastcgi-Useragent
X-Origin-CC
X-Origin-TTL
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
Uber-Trace-Id
X-PHP-Backend
X-Cdn-Origin
X-App-Version
X-Cluster-Node
X-Pass-Why
X-Urbn-Site-Id
Locale
X-ID
X-Urbn-Context-Path
X-GEO
X-Worker
X-Rocket-Nginx-Serving-Static
X-Aspnetmvc-Version
Azure-SiteName
Azure-Version
Azure-InstanceId
Azure-SlotName
Azure-RegionName
Cache-Tv-Group
X-Buckets
Node
X-FB-TRIP-ID
Sid
X-Vercel-Cache
X-Vercel-Id
X-Auth-Group-Type
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-CachedAt
Cache-Hits
CDN-Cache
CDN-Uid
CDN-PullZone
X-B3-Traceid
X-HITS
X-Server-W
X-Tumblr-Pixel-3
Alternate-Protocol
X-Pad
AMP-Access-Control-Allow-Source-Origin
X-TA-CDN-Provider
Cross-Origin-Embedder-Policy
X-DC
X-Client-Ip
X-A
X-Cache-Server
X-Tx-Id
Surrogated-Key
Wxu-Next-Region
Wxu-Next-Hostname
T-Server
Sslversion
Wxu-Next-Commit
X-A-Wwc
X-Aed
X-Bc-Bl
X-BCube-Filmed-By
Rendered-Blocks
X-A-Dgt
X-A-Dam
X-A-Dcw
X-A-Ccd
Gannett-Cam-Experience-Id
Cdn-Request-Time
Content-Secure-Policy
DB-Nickname
DCR-Decision-By
Cdn-Host
Candidate-Md5Url
X-LSADC-Cache
A
Cache-Provider
DCR-Processing-Time-Ms
Fastly-SSL
Ngx.Var.Host
Odigeo-Trace-Id
Origin-Agent-Cluster
Meta-Geo-Continent
MD5-Digest
X-Bl-Debug
Lang
Magicmarker
PFcat
X-D
X-Req
X-Rojux
X-ScT
X-SRCache-Key
X-Origin-Expires
X-Org
X-Level-Front-Cache
X-ND-Cache
X-NodeID
X-TIM-N
X-V-Cache
X-Via-Fastly
X-Viewer-Country
X-Vtex-Remote-Cache
X-Vdms-Version
X-VarnishDD-TTL
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Ig-Push-State
X-Ig-Origin-Region
X-DefElseHash
X-DefHash
X-Developer
X-Dispatcher-Server
X-Core-Value
X-Content-Age
X-Cache-NE
X-Cache-TTL-Remaining
X-Conf
X-Ec-Fail
X-Ec-GeoHdr
X-GeoIP-City
X-Gzip
X-HN
X-Generated-On
X-Fastly-Backend
X-Edge-Server
X-Epic-Correlation-Id
X-Esi-Check
X-Cache-Id
X-Custom-Header
X-Service
X-LiteSpeed-Cache-Control
Mime-Version
User-Cache-Control
Tube-Got-Eval
W
Vix-Hermes-Req-Id
V-Age
X-Platform
Tube-Got-Results
Tube-Return
X-Origin-Time
X-Access
X-Acquia-Purge-Cdn-Unconfigured
X-Node-Id
X-Nyt-Route
X-Op-Id-All
Tube-Get-Contents
X-Origin-Response-Time
X-PAYTM-SRV-ID
X-Aicache-OS
Producers
X-RateLimit-Limit-Second
X-Pubstack
Powered-By
Platform
X-Region-Sid
X-RateLimit-Remaining-Second
RNT-Machine
RNT-Time
True-Client-Country-4JS
X-Request-Time
Ssr
X-Powered-By-VTEX-Cache
Server-Host
X-Proto
X-Policy
X-AK-Request-ID
X-GeoIP
X-Geo-Header
X-Debug-Cache-Fetch
X-Csrf-Jwt
X-GeoIP-Country-Code
X-CGP
X-Clientip
X-GeoIP-Region-Code
X-Debug-Cache-Store
X-Gen-Mode
X-Fastly-Cache
X-DPWN-IS-SECURE
X-Eu-Site
X-FC-Vary-Parameters
X-Fmm-Version
X-Gdpr
X-Forwarded-Site
X-CacheTTL
X-GoCache-CacheStatus
X-Men
X-B3-Trace-ID
X-Backend-Instance
X-Micro-Cache
X-Mly-Id
X-NMSegId
X-Mvc-Supplant-Cachable
X-App-Name
X-Loc
X-Bip
X-HS-Content-Campaign-Id
X-Cache-Info
X-Hnp-Log
X-Cache-FS-Status
X-Cache-Bucket
X-Block-Status
X-Jobs
NM-Fastcgi-Cache
Req-ID
Apple-News-Services-Handled
Edge-Cache
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Tb-Optimization-Total-Bytes-Saved
X-SVT-ORM-VERSION
Esi-Enabled
Adler-Geo
X-VG-TLSProxy
X-Sn-Servicetimems
CDCHOST
Fastly-Backend-Name
X-Test
X-Thanos
X-Varnish-Director
Click-Count-Action-Start
Cdnsip
Cdncip
X-Varnish-Hostname
Click-Count-Error
X-SB
Apple-News-Services-Request-Url
X-UA-Device-Type
Country-Code
Content-Style-Type
Content-Script-Type
Ha-Gx-Prefs
X-SVT-ORM-RULES
X-Wikidot-Static-Cache
X-Server-IP
L5d-Success-Class
X-Section
X-SD-PageType
X-Scheme
Server-Info
XM
X-VTEX-Cache-Time
X-Wikidot-Backend
X-VTEX-Cache-Server
X-VG-WebCache
Host-ID
Is-Eu
L
HA-Ipaddr
HostName
X-Varnish-Beresp-Ttl
X-Dc
X-Varnishpool
Yak-Timeinfo
X-Mvc-Supplant-OutputCached
BehaviorPad-Version
X-Ec-Custom-Error
X-Depends
X-Location
X-BBC-Edge-Cache-Status
Canary
X-Cache-Aspx
X-Date
X-Human
X-Cs
X-CUA
X-We-Are-Hiring
X-Cdn-Srv
X-Hash
C-Via
X-Contensis-Viewer-Groups
AKAMAI
Cache-Key
X-Varnish-Beresp-Status
Origin-CC
Server-Ext
X-Proxied-Request
Server-Hostname
Sever-Int
X-Pool
Gh-Request-Id
Origin-EX
Req-Svc-Chain
Machine
Proxy-Firewall
Mail-Subject
NGX
X-Slack-Backend
Release
Pramga
X-Slack-Shared-Secret-Outcome
Cluster
On-Server
Origin
X-Amz-Storage-Class
X-Nginx-Cache-Key
X-Auto-Login
X-Request-Start
X-Varnish-Authentication
X-Accel-Expires-Debug
We-Hiring
X-Request-Host
Fastly-GeoIP-CountryCode
Web-Mar-Region
X-Var-Ttl
DSUID
X-NGINX-Cache
X-AIR-PT
Debug
X-Ad-Load-Variation
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
X-WA-Info
Fusion-Component-Id
Fusion-Content-Id
X-Varnish-Hits
X-MP-GENERATED-AT
X-LB-ID
X-Device-Os
X-CLOUD-TRACE-CONTEXT
X-APP
Redirect-Candidate
X-Newrelic-Synthetics
X-Tec-Api-Origin
X-Tec-Api-Version
SID
X-Tec-Api-Root
Pics-Label
Fastly-Drupal-HTML
GeoIP-Latitude
X-Content-Length
X-Via-Popv
X-Via-Popn
X-HA-Backend
X-Via-Poph
X-Zone
X-RateLimit-Reset
X-Up
CloudFront-Viewer-Country
X-VHOST
X-From
X-NCache
X-Akamai-Transformed
CDN-RequestId
X-CACHE-AGE
X-B3-Parentspanid
X-Jungle-Id
X-Cache-Backend
X-Servedbyhost
X-Nananana
Vc-Max-Age
X-LiteSpeed-Tag
X-Litespeed-Tag
X-Refresh
X-Dispatcher-Number
X-LB-NoCache
X-Nc
X-Vdms-Path
X-Parent-Response-Time
Product
Fastly-Drupal-Html
X-RequestId
X-CACHE-KEY
X-ZONE
X-CDN-Cache-Status
X-Cached-By
WP-Super-Cache
X-Wa
X-Uri
Server-ID
X-DynaTrace-JS-Agent
X-Datadome
Cdn
Resin-Trace
X-VC-TTL
X-M-Reqid
X-Render-Time
X-PERF
X-Ckpd-Fst-Backend
X-M-Log
X-ApacheServer
Datacenter
X-B3-Spanid
S-Rt
X-Origin-Cache-Key
NtCoent-Length
X-CS
X-Amz-Meta-Cb-Modifiedtime
X-Bug-Bounty
GeoIp-Country-Code
X-IAuth-Set-Uid
Uri
X-Fpc
ServerName
FSS-Cache
X-HubSpot-Correlation-Id
X-Varnish-Beresp-TTL
Locid
X-Esi
Serverhost
True-Client-Ip
X-HostName
X-SERVER-NAME
X-TX-ID
X-Nf-Country
X-Nf-Language
True-Client-IP
X-Nf-Ats-Version
X-TT-LOGID
User-Agent
X-Dynatrace-Js-Agent
Srv
X-VCache
X-Vmg-Version
GeoIP-Country-Code
Tcn
X-Akamai-Device-Characteristics
X-Srv
X-TIME
X-Info
X-Cdn-Cache-Status
X-Gamma-Serve
ServerHost
X-NewRelic-App-Data
X-Old-Content-Length
X-FPC
X-Webkit-Csp-Report-Only
CDN
Request-ID
X-Hit
CacheControlHeader
Xc-Version
X-WA
Ngx-Var-Key
X-Original-Request-Id
X-Response-Served-From
X-Vc
X-Moov-Xdn-Version
X-Vgn-Hpd-Reason
Server-Id
X-Moov-T
Expect-Staple
X-APP-VERSION
X-Cdn-Forward
X-COUNTRY
Hostname
X-NC
X-TH-Server
X-Amz-Meta-Opti
X-FL-QIT-DEBUG
Srvid
Cneonction
X-Presslabs-Stats
X-V
Cf-Ipcountry
X-Geo
X-Dispatch
X-Lb-Nocache
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-New
X-Eligible
WZWS-RAY
Cf-Device-Type
X-Rollout
Geoip-Latitude
Cloudfront-Viewer-Country
X-Platform-Server
N-Cache
Permission-Policy
PICS-Label
X-ServedByHost
X-Oracle-DMS-ECID
X-VCL-Version
X-Destination
XkeyRZ
X-Application
X-Proxy-CacheRZ
X-Via-PopN
X-Via-PopV
X-Limited
X-Ha-Backend
X-Via-PopH
Origin-Trial
X-S-Cookie
X-User
X-External-Request-Id
X-B-Cookie
Cross-Origin-Embedder-Policy-Report-Only
X-ElasticPress-Query
X-Correlation-ID
X-Internal-TTL
X-Akamai-Pragma-Client-IP
X-Ftr-Request-Id
Ohc-File-Size
X-App
X-Ua
X-Zen-Fury
Rtss
Epwk-X-Cache
X-MSEdge-Flight
Cl-Cache
X-Sigma-Backend
X-Sqd-Stime
X-VTEX-Cache-Backend-Connect-Time
Edge-Copy-Time
X-Cache-Date
X-VTEX-Cache-Backend-Header-Time
X-Instance-Name
X-Sqd-Ctime
X-MSEdge-Features
Ms-Author-Via
X-Sigma
X-Via-CDN
X-Via-Edge
X-MiniProfiler-Ids
X-Via-SSL
X-Path
X-Rocket-Build-Number
X-Litespeed-Cache-Control
X-EC-Lua
X-Check-Cacheable
X-Lb-Id
X-Serial
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Lb
WebServer
X-Branch-Name
X-Segment-20210421
Timeexpire
X-VServer
X-Acquia-Site
X-Service-Response-Time
X-Web-Server
Sm-Log-Id
X-SIPLIST1
X-Datacenter
X-API-Version
IsBot
Cmstype
Cmsid
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
Servername
X-CSRF-TOKEN
X-CDN-Origin
X-LAGOON
CountryCode
X-Amz-Meta-S3b-Last-Modified
X-Th-Server
X-Udemy-Cache-App-Namespace
X-Dw-Trace-Id
X-Ramcache
X-Amz-Meta-Sha256
X-Snapshot-Date
X-Traceid
X-Irp-Debug
X-DynaTrace
X-IN-APIGATEWAY
Warning
X-RAMCache
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
Ohc-Cache-HIT
X-Fastly-Backend-Reqs
Wpo-Cache-Status
X-Shopid
X-Shardid
Wpo-Cache-Message
Fl-Custom-Application
Ngx
X-Origin-Upstream-Status
X-IN-APIGATEWAYSSL