Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
Accept-CH
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Check
X-Drupal-Cache
X-Ua-Compatible
X-Generator
X-Cache-Status
X-Request-ID
Server-Timing
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
X-Via
Host-Header
Expect-Ct
Permissions-Policy
EagleId
Keep-Alive
Request-Context
X-Cache-Group
X-Backend
X-Robots-Tag
P3p
X-UA-Device
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
Xkey
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Server-Powered-By
Ali-Swift-Global-Savetime
Allow
X-Varnish-Cache
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-Host
X-WebKit-CSP
Cf-Railgun
X-Backend-Server
X-Server-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
Surrogate-Control
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-HW
X-Cloud-Trace-Context
Request-Id
X-Node
X-Country
Content-Location
X-Nginx-Cache-Status
X-Application-Context
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-ASPNET-VERSION
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
X-Clacks-Overhead
Cache-Tag
Rating
X-Amz-Server-Side-Encryption
X-Times
X-Rack-Cache
X-Vname
X-PC
X-TtlSet
Cross-Origin-Opener-Policy
X-Litespeed-Cache
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-FTR-Request-ID
X-Server-Name
X-Daa-Tunnel
Nginx-Cache
Accept-Ch
X-Powered-By-Plesk
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Cache-TTL
X-Cnection
X-CST
X-Webkit-Csp
X-Ac
X-ESI
X-D2id
X-Element-Page-Cache
X-GitHub-Request-Id
X-Kinja-Server
X-Kinja
X-Kinja-Revision
Edge-Control
X-Kinja-Build
X-Cdn-Fetch
Verso
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-MS-InvokeApp
X-ECACHE
AR-CACHE
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Upstream
X-Navigation-Version
X-Dw-Request-Base-Id
X-FastCGI-Cache
X-Oneagent-Js-Injection
Fastly-Restarts
SPRequestDuration
SPIisLatency
X-B3-TraceId
X-Amz-Rid
X-Mod-Pagespeed
X-Server-Lifecycle-Phase
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-SharePointHealthScore
SPRequestGuid
X-Client-IP
X-ARC
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Hash
X-Sol
X-Powered-CMS
Display
X-Middleton-Display
Pagespeed
X-Mg-S
S
X-NF-Request-ID
Edge-Cache-Tag
X-Amzn-Trace-Id
Cache-Status
X-Version
X-Ratelimit-Limit
Access-Control-Request-Method
X-Middleton-Response
Response
X-VARITI-CCR
RTSS
X-Fastly-Request-ID
Realpath
X-Forwarded-For
X-T
X-Cache-Key
X-Content-Digest
Cross-Origin-Resource-Policy
X-Ruxit-Js-Agent
X-Ratelimit-Remaining
X-TTL
X-Recruiting
X-TraceId
X-Correlation-Id
Fastcgi-Cache
X-Cached
X-MSEdge-Ref
X-ORACLE-DMS-RID
X-Varnish-TTL
X-Shield-Request-Id
Front-End-Https
MicrosoftSharePointTeamServices
X-RateLimit-Remaining
X-Ua-Browser
X-Request-Processing-Time
X-Request-Received
X-Forwarded-Proto
X-LLID
X-Frontend
TP-Cache
X-Protected-By
MS-Author-Via
X-PressLabs-Stats
Arr-Disable-Session-Affinity
Payment
Server-Node
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Public-Key-Pins
Content-MD5
Count-Hit
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Server-ID
X-Accel-Expires
X-HS-Combine-CSS
X-GUploader-UploadID
X-Distributor
X-LB-Cache
X-NODE
X-FTR-Backend-Server
X-Origin-Server
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ezoic-Cdn
X-FTR-Expires
X-Newrelic-App-Data
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Microsite
X-Request-Handler-Origin-Region
X-Www-Served-By
X-Content-Security-Policy-Report-Only
X-Activity-Id
Host
X-App-Server
X-AppVersion
X-Varnish-Server
X-Az
X-Cluster-Name
X-Amz-Meta-S3cmd-Attrs
MRF-Tech
Accept-Charset
X-Ua-Device
X-B3-TraceId-Primal
Cleartype
Mrf-Cache-Status
Cache-Tags
X-Varnish-Backend
Retry-After
Surrogate-Key
X-ORACLE-DMS-ECID
Filterid
X-Ttl
X-Goog-Metageneration
X-Unique-Id
Server-Name
X-Hits
X-Git-Hash
Access-Control-Allow-Method
X-Debug
X-Upgrade-Enabled
X-Azure-Ref
X-Envoy-Decorator-Operation
X-Logged-In
X-Load-Cache
X-Id
X-NGENIX-Cache
X-CSRF-Token
X-Geo-Country
X-Hostname
X-FB-Debug
TCN
X-Amzn-RequestId
TP-L2-Cache
X-Proxy
X-Amz-Apigw-Id
X-B
X-Tt-Trace-Host
X-Grace
X-Tt-Trace-Tag
X-TT
X-Time
X-Revision
Section-Io-Cache
Viewport
DC
X-Seen-By
X-Type
X-Fb-Rlafr
X-B3-Sampled
Healthy
X-Hcs-Proxy-Type
X-F-Cache
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Trace-Id
X-Contextid
X-Cache-Control
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Request-Guid
X-Mobile
X-XRDS-LOCATION
Fastly-SIE
X-Goog-Generation
X-Goog-Stored-Content-Encoding
Referer-Policy
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
Fastly-SWR
X-N
Paypal-Debug-Id
Content-Disposition
X-DIS-Request-ID
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Varnish-Ttl
X-Webkit-CSP
X-Varnish-Grace
X-Magnolia-Registration
X-Page-Id
X-Px
X-Origin-Cache
X-Via-JSL
X-Amz-Replication-Status
X-Debug-Info
Version
X-Ratelimit-Reset
X-Oracle-Dms-Ecid
X-Whom
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Content-Options
X-ProcessESI
X-G
X-Rid
X-Wormhole-Sdk
X-UUID
X-RemovedCookies
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Template
X-Rule
X-Tumblr-Pixel
X-Tumblr-User
X-App-Environment
X-Debug-IsPreview
X-Debug-IsConnected
VIX-Pulpo-Node
X-Hl-Ver
X-Source
NGB
VIX-Pulpo-Upstream-Status
X-Adobe-Content
X-Node-Name
X-Datadog-Sampled
X-Adobe-Loc
X-RTag
Ms-Operation-Id
X-Storage
MS-CV
Charset
X-Device-Type
X-B-Cache
X-Yottaa-Metrics
X-Proxy-Cache-Info
X-NYM-Debug-Backend
X-Region
X-Signature
X-User-Agent
X-Yottaa-Optimizations
Cross-Origin-Window-Policy
X-Wix-Request-Id
X-Cacheable-TTL
X-L-Path
X-Backend-Name
X-FW-Static
X-FW-Server
SD-X-WS
X-Environment-Context
X-FW-Type
X-FW-Dynamic
X-FW-Serve
X-Status
X-Instance
X-FW-Hash
X-FW-Version
Country
GEO-INFO
X-Is-Bot
X-Rendered-As
X-ServerID
ServerID
Countrycode
X-IPS-LoggedIn
X-Cache-Age
Amp-Access-Control-Allow-Source-Origin
X-Real-IP
X-EdgeConnect-Cache-Status
X-Cache-Grace
SRV
Akamai-GRN
X-RM-Cache-TTL
X-NWS-UUID-VERIFY
Front
X-Ismobilevalue
Liferay-Portal
X-Framework
X-Cache-Hit
X-WP-CF-Super-Cache-Active
X-Aws-Lambda-Call-Status
X-Amzn-Remapped-Content-Length
X-Language
X-AB
X-Nf-Request-Id
X-Oracle-Dms-Rid
X-Air-Pt
X-WebKit-CSP-Report-Only
X-Content-Powered-By
OT-Force-Account-Verify
X-B3-SpanId
X-Akamai-Request-ID2
X-UA
X-Servername
X-Sucuri-Cache
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Sucuri-ID
X-VC-Cache
From-Origin
X-VC
Backend
X-Api-Version
Xet-Cookie
X-Mode
X-RateLimit-Limit
X-Xrds-Location
X-URL
Accept-Language
Refresh
X-Tt-Logid
Upgrade-Insecure-Requests
Webserver
X-Nginx-Cache
Access-Control-Request-Headers
X-Handled-By
X-Cache-Time
X-Cache-Status-Check
X-HTML-Minification-Powered-By
X-SRV
Meta-Geo
X-SaId
X-Rn-Rsrv
X-RCS-CacheZone
X-Rewrite-Enabled
X-DataDome
Filters
X-JoinUs
X-UPSTREAM-Address
Webcakes-Region
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Provided-By
X-Cache-Operation
TWC-GeoIP-Country
TWC-Locale-Group
Cache
Webcakes-App-Name
LB
X-PHP-Host
X-Tumblr-Pixel-2
X-Varnish-Age
Webcakes-App-Version
X-R9-Blue-Green-Version
X-Origin-Hint
X-Cache-Rule
TWC-Device-Class
X-Xfnlog-Site
Property-Id
ServedBy
X-Labrador-Cache-Channel
X-S
TWC-Privacy
X-Is-Mobile
Atl-Traceid
X-Httpd
X-Cluster
X-Container-Uri
X-Fetched-On
X-Tb
X-Cms-Context
X-Reqid
X-Scope-Id
X-Tcp-Rtt
X-ProxyCache-Key
X-Locale
X-Logging-Id
X-Endurance-Cache-Level
X-Lambda-Id
X-Served-From
X-Origin-Date
X-Is-Tablet
X-ProxyCache-Status
X-Is-Supported-Browser
Section-Io-Id
X-Webstats-RespID
X-Skip-Cache
X-Akamai-Edgescape
X-BYPASS-REASON
X-Generated-By
X-Browser-Name
X-Hosted-By
X-Forwarded-Host
X-Adobe-Source
X-Git-Commit
X-Is-Desktop
X-Geo-Region
X-Accel-Version
X-No-Session
X-Ms-Version
X-Frame-Option
X-Format
X-Optimistic-Header
X-Mg-Request-UUID
Url
X-Loop
X-Cache-Host
X-IPLB-Request-ID
Apigw-Requestid
Selected-Fe
X-Origin
X-Alternate-Cache-Key
Mn-Server-Ip
Web-Mar-Node
X-IPLB-Instance
X-Ms-Request-Id
X-Upstream-Ht
X-Restarts
X-Web-Node
X-Upstream-Ct
X-Site-Version
X-Varnish-Beresp-Grace
X-Varnish-Cache-Hits
X-VCT
X-Redis-Cache
X-Tncms
X-Storefront-Renderer-Rendered
X-Proxy-Build
X-Shopify-Stage
X-Timing-Wait
X-Request-URI
X-Edge-Location
X-SayCDN-TTL
X-Soup
X-Say-TTL
X-RID
X-Say-Cacheable
X-VWS-Id
X-Director
X-INCAP-ABP
X-Extlb
X-Proxied
X-LJ-Flow-ID
X-Cloudmap
X-Routing-Service
Xserver
X-AWS-Id
X-Zipkin-Id
X-Sorting-Hat-PodId
X-Cache-Debug
Onion-Location
X-Sorting-Hat-ShopId
X-ShardId
X-ShopId
X-GeoCode
X-Connection-Hash
X-Detected-As
X-GeoCountry
X-Vcl-Version
X-Azure-Ref-OriginShield
Expiry
Frame-Options
X-Lagoon
Cdn-Requestid
X-CDN-Forward
WPO-Cache-Status
WPO-Cache-Message
X-Cache-Expired-At
Source
X-CMSURLCustom
X-Fastly-Request-Id
X-Generation-Time
X-Shield-Cache-Expires
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
X-Thinkindot-L3
Thinkindot-Control
X-Vcache
X-B3-Traceid
Protected
X-WP-CF-Super-Cache-Cookies-Bypass
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
Fastcgi-Useragent
X-Origin-TTL
Environment
X-ECache
X-Cdn-Origin
Priority
X-Origin-CC
X-Proxy-Cache-Status
X-Pass-Why
X-PHP-Backend
X-Cache-Action
X-App-Version
X-Vercel-Cache
Uber-Trace-Id
X-Vercel-Id
X-Worker
X-Rocket-Nginx-Serving-Static
Cache-Hits
Sid
X-ID
Azure-Version
Azure-SiteName
Azure-InstanceId
Azure-SlotName
Azure-RegionName
CF-IPCountry
X-Aspnetmvc-Version
X-Cluster-Node
Node
X-GEO
X-Buckets
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-XRDS-Location
CDN-Cache
CDN-CachedAt
X-TA-CDN-Provider
CDN-RequestPullCode
CDN-EdgeStorageId
Cross-Origin-Embedder-Policy
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
Cache-Tv-Group
X-FB-TRIP-ID
X-Fastcgi-Cache
X-Tumblr-Pixel-3
X-Auth-Group-Type
AMP-Access-Control-Allow-Source-Origin
X-Cache-Server
X-Pad
DB-Nickname
X-Server-W
X-RateLimit-Reset
X-A
X-Client-Ip
Alternate-Protocol
Magicmarker
X-A-Dgt
X-Service
X-A-Dam
X-A-Ccd
X-Vtex-Remote-Cache
X-ND-Cache
X-Ec-Fail
Gannett-Cam-Experience-Id
X-A-Dcw
X-Op-Id-All
X-Org
X-A-Wwc
Wxu-Next-Region
X-Developer
X-DefElseHash
X-Dispatcher-Server
X-DefHash
X-Edge-Server
X-BCube-Filmed-By
A
X-Gzip
X-Bc-Bl
X-Via-Fastly
X-GeoIP-City
Cdn-Request-Time
Cdn-Host
Candidate-Md5Url
X-Generated-On
Content-Secure-Policy
Wxu-Next-Commit
Wxu-Next-Hostname
DCR-Decision-By
DCR-Processing-Time-Ms
X-D
X-Epic-Correlation-Id
X-Level-Front-Cache
X-Ig-Origin-Region
X-Ig-Push-State
X-Esi-Check
X-Ec-GeoHdr
Lang
X-SRCache-Key
X-Cache-Id
MD5-Digest
X-Varnish-Remaining-TTL
Surrogated-Key
Origin-Agent-Cluster
T-Server
X-ScT
X-Dc
X-Varnish-CookieINHashed-On
X-V-Cache
X-Varnish-CookieHashed-On
X-Aed
Rendered-Blocks
X-TIM-N
X-Cache-TTL-Remaining
X-Cache-NE
X-Rojux
X-Conf
X-Viewer-Country
X-Vdms-Version
X-Core-Value
Odigeo-Trace-Id
X-Req
Sslversion
Meta-Geo-Continent
X-Custom-Header
X-Bl-Debug
Ngx.Var.Host
Mime-Version
HostName
X-LiteSpeed-Cache-Control
V-Age
Tube-Got-Eval
Ssr
Click-Count-Action-Start
RNT-Time
X-Cache-Info
Click-Count-Error
X-Cache-FS-Status
Tube-Return
Tube-Got-Results
X-Fmm-Version
RNT-Machine
X-Fastly-Backend
Server-Host
Esi-Enabled
Host-ID
X-Content-Age
Origin
Tube-Get-Contents
Is-Eu
X-Debug-Cache-Store
X-Bip
NM-Fastcgi-Cache
X-Gdpr
X-Debug-Cache-Fetch
X-DPWN-IS-SECURE
X-Clientip
Producers
Edge-Cache
X-CacheTTL
Country-Code
X-Cdn-Srv
Powered-By
PFcat
Platform
Fastly-Backend-Name
Req-ID
X-Jobs
X-SB
X-Request-Time
X-Scheme
X-VTEX-Cache-Time
X-Acquia-Purge-Cdn-Unconfigured
X-VTEX-Cache-Server
X-B3-Trace-ID
X-Region-Sid
Vix-Hermes-Req-Id
X-Powered-By-VTEX-Cache
X-Pubstack
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Ad-Load-Variation
X-Server-IP
X-Varnish-Director
X-Aicache-OS
X-Varnish-Hostname
X-VarnishDD-TTL
X-VG-WebCache
X-VG-TLSProxy
X-UA-Device-Type
X-Thanos
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-SVT-ORM-VERSION
X-Tb-Optimization-Total-Bytes-Saved
X-Test
X-Policy
X-Proto
X-Men
X-LSADC-Cache
X-Loc
X-Micro-Cache
XM
X-Wikidot-Static-Cache
X-Mly-Id
X-Amz-Storage-Class
X-HN
X-Geo-Header
Cache-Provider
X-GeoIP
X-GoCache-CacheStatus
Adler-Geo
AKAMAI
X-Wikidot-Backend
X-Mvc-Supplant-Cachable
X-Origin-Expires
X-NMSegId
X-Origin-Time
X-PAYTM-SRV-ID
X-Tx-Id
X-Platform
X-Node-Id
X-Nyt-Route
X-NodeID
X-Varnish-Beresp-Ttl
User-Cache-Control
X-DC
X-Tec-Api-Root
X-Tec-Api-Version
X-HITS
X-Tec-Api-Origin
X-App-Name
X-BBC-Edge-Cache-Status
X-Block-Status
X-Auto-Login
X-Backend-Instance
X-GeoIP-Country-Code
X-Origin-Response-Time
X-Pool
X-WA-Info
X-Nginx-Cache-Key
X-Mvc-Supplant-OutputCached
X-We-Are-Hiring
X-Proxied-Request
X-Request-Start
X-Varnish-Beresp-Status
X-Varnishpool
X-Varnish-Authentication
X-Var-Ttl
X-SD-PageType
X-Section
X-Location
X-HS-Content-Campaign-Id
X-Date
X-Depends
X-Csrf-Jwt
X-Contensis-Viewer-Groups
X-Cache-Bucket
Yak-Timeinfo
X-Eu-Site
X-Fastly-Cache
X-Hash
X-Hnp-Log
X-GeoIP-Region-Code
X-Gen-Mode
X-FC-Vary-Parameters
X-Forwarded-Site
X-Cache-Aspx
X-CGP
Ha-Gx-Prefs
HA-Ipaddr
Gh-Request-Id
Fusion-Content-Id
Fastly-SSL
X-Cs
L
L5d-Success-Class
On-Server
Origin-CC
Fusion-Component-Id
Fusion-Template-Id
Machine
Fastly-GeoIP-CountryCode
DSUID
C-Via
Cache-Key
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Canary
CDCHOST
Content-Script-Type
Content-Style-Type
Cluster
Cdnsip
Cdncip
Origin-EX
Mail-Subject
X-Accel-Expires-Debug
Req-Svc-Chain
We-Hiring
W
True-Client-Country-4JS
Release
X-Access
Proxy-Firewall
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Source
X-AK-Request-ID
X-NGINX-Cache
X-AIR-PT
X-Human
Server-Info
Web-Mar-Region
X-Ec-Custom-Error
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Sever-Int
Pramga
Server-Ext
X-Request-Host
X-CUA
NGX
Server-Hostname
X-Device-Os
Debug
X-Origin-Cache-Key
X-Varnish-Hits
BehaviorPad-Version
X-From
Redirect-Candidate
X-Up
X-Zone
X-NCache
X-LB-ID
X-Akamai-Transformed
X-Via-Popn
X-Jungle-Id
X-Via-Popv
X-HA-Backend
Pics-Label
Fastly-Drupal-HTML
X-MP-GENERATED-AT
X-APP
X-Via-Poph
X-Datadome
CDN-RequestId
X-Cache-Backend
X-Refresh
X-VHOST
X-Vdms-Path
CloudFront-Viewer-Country
X-CACHE-AGE
X-Parent-Response-Time
SID
X-Content-Length
WP-Super-Cache
X-B3-Parentspanid
X-Servedbyhost
X-LiteSpeed-Tag
X-Uri
X-Newrelic-Synthetics
X-Nc
GeoIP-Latitude
X-LB-NoCache
X-CDN-Cache-Status
X-ApacheServer
X-B3-Spanid
X-Render-Time
X-PERF
Datacenter
X-VC-TTL
X-CACHE-KEY
X-Nananana
X-M-Log
X-M-Reqid
Fastly-Drupal-Html
X-DynaTrace-JS-Agent
Vc-Max-Age
X-Litespeed-Tag
Resin-Trace
X-Wa
Server-ID
X-ZONE
X-Cached-By
NtCoent-Length
Cdn
Product
X-RequestId
X-Dispatcher-Number
X-VCache
GeoIp-Country-Code
Locid
X-CS
X-Amz-Meta-Cb-Modifiedtime
X-Ckpd-Fst-Backend
X-Fpc
FSS-Cache
X-IAuth-Set-Uid
X-NewRelic-App-Data
X-TX-ID
X-Varnish-Beresp-TTL
X-Esi
X-Bug-Bounty
True-Client-Ip
Serverhost
X-Original-Request-Id
X-Response-Served-From
X-Srv
S-Rt
X-SERVER-NAME
X-HostName
True-Client-IP
ServerName
X-Nf-Language
X-Nf-Ats-Version
X-Old-Content-Length
Uri
X-Nf-Country
X-TT-LOGID
X-HubSpot-Correlation-Id
Tcn
Ngx-Var-Key
CDN
Cf-Ipcountry
Srv
X-Oracle-DMS-ECID
X-TIME
X-Cdn-Forward
GeoIP-Country-Code
X-Vgn-Hpd-Reason
X-FPC
X-Dynatrace-Js-Agent
Request-ID
X-Cdn-Cache-Status
X-Moov-Xdn-Version
X-TH-Server
CacheControlHeader
X-Vc
X-WA
X-Vmg-Version
X-Akamai-Device-Characteristics
User-Agent
X-Moov-T
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-Dispatch
X-Gamma-Serve
ServerHost
Server-Id
Hostname
X-COUNTRY
X-APP-VERSION
Xc-Version
X-Info
X-NC
Srvid
X-FL-QIT-DEBUG
Geoip-Latitude
Cf-Device-Type
X-Webkit-Csp-Report-Only
X-Geo
X-Presslabs-Stats
X-Hit
X-S-Cookie
X-User
X-External-Request-Id
X-Application
X-B-Cookie
Expect-Staple
X-Destination
X-Lb-Nocache
Cross-Origin-Embedder-Policy-Report-Only
Cloudfront-Viewer-Country
X-Zen-Fury
Origin-Trial
X-Amz-Meta-Opti
Cneonction
X-ServedByHost
X-VCL-Version
Ohc-File-Size
Epwk-X-Cache
X-Rocket-Build-Number
X-Limited
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Ha-Backend
X-Sigma
X-Sigma-Backend
PICS-Label
X-Cache-Date
X-Instance-Name
X-V
X-Ua
X-VServer
X-New
X-Segment-20210421
X-API-Version
X-Rollout
X-Platform-Server
X-Akamai-Pragma-Client-IP
X-App
N-Cache
Permission-Policy
WZWS-RAY
X-Correlation-ID
X-Eligible
Rtss
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Proxy-CacheRZ
X-MiniProfiler-Ids
X-Branch-Name
XkeyRZ
X-Check-Cacheable
X-Serial
X-Sqd-Stime
X-Lb-Id
X-Sqd-Ctime
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Lb
Timeexpire
X-Fastly-Backend-Reqs
X-Datacenter
Cmstype
Cmsid
X-MSEdge-Features
X-MSEdge-Flight
X-Acquia-Site
X-Ftr-Request-Id
X-ElasticPress-Query
Sm-Log-Id
X-Internal-TTL
Ngx
X-Acquia-Application-Trace
X-Service-Response-Time
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Litespeed-Cache-Control
Servername
X-LAGOON
CountryCode
X-CSRF-TOKEN
Edge-Copy-Time
X-VTEX-Cache-Backend-Connect-Time
X-Via-SSL
X-EC-Lua
X-Via-CDN
X-Via-Edge
Wpo-Cache-Status
X-VTEX-Cache-Backend-Header-Time
Fl-Custom-Application
X-DataCenter
Warning
X-Web-Server
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Sha256
X-Snapshot-Date
X-Ramcache
X-Requestid
X-RAMCache
X-Th-Server
X-Udemy-Cache-App-Namespace
X-Dw-Trace-Id
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
Ohc-Cache-HIT
X-Shopid
X-Shardid
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Origin-Upstream-Status
Wpo-Cache-Message