Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Check
X-Drupal-Cache
X-Ua-Compatible
X-Generator
X-Cache-Status
Server-Timing
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Permissions-Policy
X-Via
Host-Header
EagleId
Keep-Alive
X-Cache-Group
Request-Context
X-Robots-Tag
X-Backend
X-UA-Device
X-AH-Environment
X-Hacker
X-Proxy-Cache
X-Server
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
Xkey
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Server-Powered-By
Ali-Swift-Global-Savetime
Allow
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-WebKit-CSP
X-Host
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Cf-Railgun
X-Backend-Server
X-Server-Id
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
Surrogate-Control
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-HW
X-Node
Request-Id
X-Cloud-Trace-Context
X-Litespeed-Cache
X-Country
Content-Location
X-Nginx-Cache-Status
X-Application-Context
Accept-Ch-Lifetime
X-Nginx-Upstream-Cache-Status
X-ASPNET-VERSION
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
Cache-Tag
X-Url
X-Clacks-Overhead
Rating
X-Amz-Server-Side-Encryption
X-Times
X-Rack-Cache
X-PC
X-TtlSet
X-Vname
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Server-Name
X-Browser-Type
X-Daa-Tunnel
Accept-Ch
AR-Request-ID
AR-PoweredBy
AR-SID
AR-ATIME
Nginx-Cache
X-Powered-By-Plesk
X-Cache-TTL
X-Cnection
X-FTR-Request-ID
X-ESI
X-Ac
X-GitHub-Request-Id
Verso
Edge-Control
X-Element-Page-Cache
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-CST
X-D2id
X-MS-InvokeApp
AR-CACHE
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Upstream
X-Dw-Request-Base-Id
Fastly-Restarts
X-Navigation-Version
X-B3-TraceId
X-Webkit-Csp
X-ECACHE
SPIisLatency
SPRequestDuration
X-FastCGI-Cache
X-Mod-Pagespeed
X-Amz-Rid
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-PDP-UNCACHING-HASH
SPRequestGuid
X-Client-IP
X-SharePointHealthScore
X-ARC
X-Goog-Hash
X-Kinsta-Cache
X-Edge-Location-Klb
X-Middleton-Display
Display
X-Sol
Pagespeed
X-Oneagent-Js-Injection
X-Powered-CMS
X-Mg-S
X-Ratelimit-Limit
X-Amzn-Trace-Id
Edge-Cache-Tag
S
Cache-Status
X-Version
Access-Control-Request-Method
Response
X-Middleton-Response
X-VARITI-CCR
X-Ratelimit-Remaining
X-NF-Request-ID
RTSS
Realpath
X-Forwarded-For
X-T
Cross-Origin-Resource-Policy
X-Cache-Key
X-Content-Digest
X-TTL
X-Correlation-Id
X-Cached
Fastcgi-Cache
X-Recruiting
X-ORACLE-DMS-RID
X-Fastly-Request-ID
X-MSEdge-Ref
X-Shield-Request-Id
X-TraceId
MicrosoftSharePointTeamServices
Front-End-Https
X-Forwarded-Proto
X-Ua-Browser
X-PressLabs-Stats
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ruxit-Js-Agent
X-Request-Processing-Time
Payment
X-Frontend
TP-Cache
X-Request-Received
X-LLID
Arr-Disable-Session-Affinity
X-HS-Cache-Config
X-HS-Hub-Id
Server-Node
X-HS-Content-Id
X-Protected-By
Count-Hit
Public-Key-Pins
MS-Author-Via
X-Newrelic-App-Data
X-Server-ID
Content-MD5
X-GUploader-UploadID
X-Accel-Expires
X-LB-Cache
X-HS-Combine-CSS
X-RateLimit-Remaining
X-Varnish-TTL
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Distributor
X-Origin-Server
X-NODE
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Surrogate-Key
X-Ezoic-Cdn
X-ORACLE-DMS-ECID
X-Request-Handler-Origin-Region
X-Microsite
X-Content-Security-Policy-Report-Only
X-HP-Webp
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Jurisdiction
X-HP-Trace-Id
X-FTR-Backend
X-Country-Code-Real
X-Www-Served-By
Accept-Charset
X-App-Server
Mrf-Cache-Status
MRF-Tech
Host
X-B3-TraceId-Primal
X-Varnish-Server
X-Az
X-Ua-Device
X-Cluster-Name
X-AppVersion
X-Amz-Meta-S3cmd-Attrs
Cache-Tags
Cleartype
X-Activity-Id
Retry-After
X-Varnish-Backend
X-Ttl
X-Goog-Metageneration
Filterid
X-FTR-Expires
X-Unique-Id
X-Hits
X-Debug
Server-Name
X-Git-Hash
Access-Control-Allow-Method
X-Aspnet-Version
X-Logged-In
X-Varnish-Ttl
X-Load-Cache
X-Upgrade-Enabled
X-Id
X-Azure-Ref
X-NGENIX-Cache
X-Envoy-Decorator-Operation
X-FB-Debug
X-CSRF-Token
X-Geo-Country
TCN
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Hostname
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Seen-By
TP-L2-Cache
X-TT
Section-Io-Cache
X-B
X-Cache-Control
X-Request-Guid
X-Grace
X-Revision
Healthy
Viewport
X-Type
DC
X-Proxy
X-Contextid
X-B3-Sampled
X-Trace-Id
X-Fb-Rlafr
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Time
Fastly-SWR
X-F-Cache
Fastly-SIE
X-CCDN-Origin-Time
X-N
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Content-Disposition
X-Ratelimit-Reset
X-Mobile
Paypal-Debug-Id
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Nf-Request-Id
X-Varnish-Grace
Referer-Policy
X-Amz-Replication-Status
X-XRDS-LOCATION
X-Webkit-CSP
X-Origin-Cache
X-Magnolia-Registration
Pinterest-Version
X-Via-JSL
X-Pinterest-Rid
Pinterest-Generated-By
X-DIS-Request-ID
X-Debug-Info
X-Page-Id
X-Wormhole-Sdk
X-Px
X-Oracle-Dms-Ecid
Version
X-Ismobilevalue
Amp-Access-Control-Allow-Source-Origin
X-Content-Options
X-RemovedCookies
X-ProcessESI
X-G
X-Rid
X-Adobe-Loc
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Source
X-Adobe-Content
X-Tumblr-Pixel
X-App-Environment
X-Rule
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Node-Name
X-Debug-IsPreview
X-Debug-IsConnected
X-Datadog-Trace-Id
X-Tumblr-User
X-Wix-Request-Id
X-Yottaa-Metrics
X-UUID
X-Yottaa-Optimizations
NGB
X-Template
X-NYM-Debug-Backend
X-Whom
Cross-Origin-Window-Policy
VIX-Pulpo-Node
X-Region
X-Storage
X-Instance
VIX-Pulpo-Upstream-Status
GEO-INFO
MS-CV
Ms-Operation-Id
X-Device-Type
X-Rendered-As
X-RTag
X-Proxy-Cache-Info
X-Hl-Ver
X-Is-Bot
X-Signature
X-Status
X-Backend-Name
X-B-Cache
X-Cacheable-TTL
X-Datadog-Sampled
X-User-Agent
X-ServerID
X-L-Path
X-FW-Version
X-FW-Hash
X-FW-Dynamic
X-Environment-Context
X-FW-Serve
X-FW-Server
SD-X-WS
X-FW-Type
Country
X-FW-Static
X-Cache-Age
X-URL
Charset
X-RM-Cache-TTL
SRV
Countrycode
Front
Akamai-GRN
ServerID
X-IPS-LoggedIn
X-NWS-UUID-VERIFY
X-Real-IP
X-Framework
X-EdgeConnect-Cache-Status
X-WP-CF-Super-Cache-Active
X-Cache-Grace
X-AB
X-ECache
X-Xrds-Location
Liferay-Portal
X-Language
X-B3-SpanId
X-Cache-Hit
X-Amzn-Remapped-Content-Length
X-Oracle-Dms-Rid
X-Air-Pt
X-Content-Powered-By
X-Akamai-Request-ID2
X-Fastly-Request-Id
X-DataDome
X-Api-Version
X-WebKit-CSP-Report-Only
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
Accept-Language
X-VC
OT-Force-Account-Verify
X-Servername
X-UA
X-Sucuri-ID
X-Sucuri-Cache
X-VC-Cache
Xet-Cookie
From-Origin
X-Mode
LB
Webserver
Refresh
X-Tt-Logid
X-Cache-Status-Check
X-SRV
Access-Control-Request-Headers
Backend
X-HTML-Minification-Powered-By
X-Nginx-Cache
X-Handled-By
X-Mg-Request-UUID
Upgrade-Insecure-Requests
X-SaId
X-Container-Uri
X-Rewrite-Enabled
X-Rn-Rsrv
Meta-Geo
Filters
X-UPSTREAM-Address
X-Cache-Time
X-JoinUs
X-Git-Commit
X-RCS-CacheZone
TWC-Privacy
Xserver
Webcakes-Region
Webcakes-App-Name
X-Origin-Hint
Webcakes-App-Version
X-Origin-Date
X-Webstats-RespID
X-Request-URI
X-PHP-Host
X-Varnish-Age
X-Generated-By
TWC-Device-Class
TWC-Connection-Speed
X-RateLimit-Limit
X-Hosted-By
X-Labrador-Cache-Channel
TWC-GeoIP-Country
X-Provided-By
X-Adobe-Source
X-S
Property-Id
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Forwarded-Host
X-Tumblr-Pixel-2
X-ProxyCache-Status
X-ProxyCache-Key
X-Served-From
Section-Io-Id
ServedBy
Atl-Traceid
Apigw-Requestid
X-Restarts
Mn-Server-Ip
Web-Mar-Node
X-Redis-Cache
X-Reqid
Url
X-R9-Blue-Green-Version
X-Cms-Context
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Tablet
X-Is-Desktop
X-Akamai-Edgescape
X-Fetched-On
X-Format
X-Geo-Region
X-Lambda-Id
X-Locale
X-Tb
X-Tcp-Rtt
X-Tncms
X-Storefront-Renderer-Rendered
X-Vcl-Version
X-Logging-Id
X-Loop
X-No-Session
X-Skip-Cache
X-Httpd
X-Xfnlog-Site
X-BYPASS-REASON
X-Shopify-Stage
X-Browser-Name
X-Site-Version
X-Cache-Host
X-Cache-Debug
X-Alternate-Cache-Key
X-Web-Node
Selected-Fe
X-Upstream-Ht
X-Upstream-Ct
X-Soup
X-Timing-Wait
X-Origin
X-Optimistic-Header
X-Accel-Version
X-Proxy-Build
X-Varnish-Beresp-Grace
X-Varnish-Cache-Hits
X-Detected-As
X-Say-TTL
X-Frame-Option
X-Director
X-Scope-Id
X-SayCDN-TTL
X-Say-Cacheable
X-IPLB-Instance
X-VCT
X-IPLB-Request-ID
X-Cluster
X-Extlb
X-LJ-Flow-ID
X-Proxied
X-Cloudmap
X-AWS-Id
X-Vcache
X-ShopId
X-Edge-Location
Expiry
Onion-Location
Cache
X-Cache-Rule
X-Connection-Hash
X-VWS-Id
X-Zipkin-Id
X-Cache-Operation
X-RID
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Routing-Service
X-Ms-Version
X-Cache-Expired-At
X-Ms-Request-Id
X-INCAP-ABP
X-Aws-Lambda-Call-Status
X-Lagoon
X-Endurance-Cache-Level
Source
Cdn-Requestid
WPO-Cache-Message
WPO-Cache-Status
X-GeoCode
X-GeoCountry
Frame-Options
X-CDN-Forward
X-WP-CF-Super-Cache-Cookies-Bypass
X-Azure-Ref-OriginShield
Priority
X-Fastcgi-Cache
Environment
Protected
X-Cache-Action
X-Proxy-Cache-Status
CF-IPCountry
Fastcgi-Useragent
X-Generation-Time
X-Origin-CC
X-Origin-TTL
Uber-Trace-Id
X-PHP-Backend
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Shield-Cache-Expires
Thinkindot-Control
X-Cdn-Origin
X-Cluster-Node
X-Thinkindot-L3
Thinkindot-CacheControl-Type
TDXMobile
X-CMSURLCustom
X-App-Version
Thinkindot-CacheControl
X-Pass-Why
X-Urbn-Site-Id
X-Urbn-Context-Path
X-ID
Locale
X-GEO
X-Rocket-Nginx-Serving-Static
X-Worker
X-Aspnetmvc-Version
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
X-Buckets
Azure-RegionName
Node
Cache-Tv-Group
Sid
X-XRDS-Location
X-FB-TRIP-ID
X-Auth-Group-Type
X-Vercel-Cache
X-Vercel-Id
CDN-PullZone
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
CDN-Uid
Cache-Hits
X-B3-Traceid
X-Server-W
Cross-Origin-Embedder-Policy
X-Tumblr-Pixel-3
Alternate-Protocol
X-Pad
X-TA-CDN-Provider
AMP-Access-Control-Allow-Source-Origin
X-Client-Ip
X-DC
X-Tx-Id
X-A
X-Cache-Server
Surrogated-Key
T-Server
X-A-Wwc
Sslversion
PFcat
Rendered-Blocks
Wxu-Next-Commit
Wxu-Next-Hostname
Origin-Agent-Cluster
X-A-Dcw
X-A-Ccd
X-A-Dgt
Wxu-Next-Region
X-Aed
X-A-Dam
Fastly-SSL
Cdn-Request-Time
Content-Secure-Policy
DB-Nickname
Cdn-Host
Candidate-Md5Url
X-LSADC-Cache
A
Cache-Provider
DCR-Decision-By
DCR-Processing-Time-Ms
MD5-Digest
Meta-Geo-Continent
Ngx.Var.Host
Magicmarker
Lang
X-Bc-Bl
Gannett-Cam-Experience-Id
Odigeo-Trace-Id
X-Content-Age
X-Req
X-Rojux
X-ScT
X-Origin-Expires
X-Op-Id-All
X-Ig-Push-State
X-ND-Cache
X-NodeID
X-SRCache-Key
X-TIM-N
X-Vdms-Version
X-Via-Fastly
X-Vtex-Remote-Cache
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-V-Cache
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Ig-Origin-Region
X-HN
X-Custom-Header
X-DefElseHash
X-DefHash
X-Conf
X-Cache-TTL-Remaining
X-Bl-Debug
X-Cache-Id
X-Cache-NE
X-Developer
X-Dispatcher-Server
X-Fastly-Backend
X-GeoIP-City
X-Gzip
X-Esi-Check
X-Epic-Correlation-Id
X-Ec-Fail
X-Ec-GeoHdr
X-Edge-Server
X-BCube-Filmed-By
X-D
X-Service
Mime-Version
X-LiteSpeed-Cache-Control
User-Cache-Control
X-Core-Value
X-Csrf-Jwt
X-CGP
X-DPWN-IS-SECURE
X-Cache-Bucket
X-Cache-FS-Status
X-Cache-Info
X-Block-Status
X-CacheTTL
X-Eu-Site
X-Generated-On
X-Geo-Header
X-GeoIP
X-Gen-Mode
X-Forwarded-Site
X-Fastly-Cache
X-FC-Vary-Parameters
X-Fmm-Version
X-Bip
X-B3-Trace-ID
True-Client-Country-4JS
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Ssr
RNT-Time
Producers
Req-ID
RNT-Machine
Tube-Return
V-Age
X-AK-Request-ID
X-Amz-Storage-Class
X-App-Name
X-GeoIP-Country-Code
X-Aicache-OS
X-Acquia-Purge-Cdn-Unconfigured
Vix-Hermes-Req-Id
W
X-Access
X-Backend-Instance
X-GeoIP-Region-Code
X-Tb-Optimization-Total-Bytes-Saved
X-Test
X-Thanos
X-UA-Device-Type
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Scheme
X-Section
X-Server-IP
X-Sn-Servicetimems
X-Varnish-Director
X-Varnish-Hostname
X-Wikidot-Backend
X-Wikidot-Static-Cache
XM
Server-Info
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-VG-TLSProxy
X-VG-WebCache
X-Viewer-Country
X-SB
X-Request-Time
X-Men
X-Micro-Cache
X-Mly-Id
X-Mvc-Supplant-Cachable
X-Loc
X-Level-Front-Cache
X-GoCache-CacheStatus
X-Hnp-Log
X-HS-Content-Campaign-Id
X-NMSegId
X-Org
X-Pubstack
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Region-Sid
X-Powered-By-VTEX-Cache
X-Policy
X-Origin-Response-Time
X-PAYTM-SRV-ID
X-Platform
Powered-By
X-Jobs
L
Is-Eu
HA-Ipaddr
CDCHOST
Country-Code
NM-Fastcgi-Cache
Content-Script-Type
Content-Style-Type
Ha-Gx-Prefs
Click-Count-Error
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Esi-Enabled
Fastly-Backend-Name
Apple-News-Services-Host
Adler-Geo
AKAMAI
Apple-News-Services-Handled
Cdncip
L5d-Success-Class
Cdnsip
Click-Count-Action-Start
Platform
X-Dc
X-Varnish-Beresp-Ttl
HostName
X-HITS
X-Var-Ttl
Cache-Key
X-Clientip
X-Slack-Backend
Edge-Cache
X-Slack-Shared-Secret-Outcome
X-Cdn-Srv
X-Varnish-Beresp-Status
DSUID
X-Cache-Aspx
Server-Ext
Origin-CC
Origin-EX
X-Contensis-Viewer-Groups
Gh-Request-Id
X-Varnish-Authentication
X-CUA
Pramga
X-Request-Host
X-Depends
X-Proto
Release
Proxy-Firewall
X-Ec-Custom-Error
X-Request-Start
X-Debug-Cache-Store
X-Pool
Origin
Fastly-GeoIP-CountryCode
C-Via
Req-Svc-Chain
X-Debug-Cache-Fetch
X-Date
X-SD-PageType
Host-ID
X-We-Are-Hiring
X-Accel-Expires-Debug
Mail-Subject
On-Server
Machine
BehaviorPad-Version
X-Human
Cluster
We-Hiring
NGX
Web-Mar-Region
Yak-Timeinfo
X-Mvc-Supplant-OutputCached
X-Hash
Sever-Int
X-Nginx-Cache-Key
Server-Hostname
X-Origin-Time
Server-Host
X-BBC-Edge-Cache-Status
X-Varnishpool
Canary
X-Cs
X-Auto-Login
X-Nyt-Route
X-Node-Id
X-Location
X-Proxied-Request
X-Gdpr
X-NGINX-Cache
X-AIR-PT
Debug
Fusion-Content-Id
Fusion-Component-Id
X-Ad-Load-Variation
X-WA-Info
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Deployment-Id
X-MP-GENERATED-AT
X-LB-ID
X-Varnish-Hits
X-APP
X-Device-Os
Redirect-Candidate
X-Newrelic-Synthetics
X-CLOUD-TRACE-CONTEXT
X-Tec-Api-Root
X-Tec-Api-Version
SID
X-Tec-Api-Origin
X-HA-Backend
X-Content-Length
GeoIP-Latitude
Pics-Label
X-Via-Popv
Fastly-Drupal-HTML
X-Via-Popn
X-Via-Poph
X-Zone
X-RateLimit-Reset
X-From
X-Up
X-VHOST
CloudFront-Viewer-Country
X-NCache
X-Akamai-Transformed
X-CACHE-AGE
CDN-RequestId
X-Jungle-Id
X-Cache-Backend
X-Nananana
X-Servedbyhost
X-B3-Parentspanid
X-LiteSpeed-Tag
X-Litespeed-Tag
X-Refresh
X-Vdms-Path
X-Nc
X-LB-NoCache
X-Dispatcher-Number
Vc-Max-Age
X-Parent-Response-Time
Fastly-Drupal-Html
Product
X-ZONE
X-RequestId
X-CACHE-KEY
X-CDN-Cache-Status
WP-Super-Cache
X-Wa
X-Cached-By
Server-ID
X-Uri
X-DynaTrace-JS-Agent
Datacenter
X-PERF
X-Datadome
Cdn
Resin-Trace
X-M-Reqid
X-VC-TTL
X-Ckpd-Fst-Backend
X-ApacheServer
X-Render-Time
X-M-Log
X-B3-Spanid
S-Rt
X-Origin-Cache-Key
X-Bug-Bounty
NtCoent-Length
X-Amz-Meta-Cb-Modifiedtime
GeoIp-Country-Code
X-CS
X-IAuth-Set-Uid
FSS-Cache
Uri
ServerName
X-Fpc
X-Varnish-Beresp-TTL
X-HubSpot-Correlation-Id
True-Client-Ip
Serverhost
X-Esi
Locid
X-HostName
X-SERVER-NAME
X-TX-ID
X-Nf-Country
X-Nf-Ats-Version
True-Client-IP
X-Nf-Language
X-TT-LOGID
User-Agent
Srv
X-Vmg-Version
Tcn
X-Akamai-Device-Characteristics
X-VCache
GeoIP-Country-Code
X-TIME
X-Srv
X-FPC
X-Old-Content-Length
X-Cdn-Cache-Status
X-Gamma-Serve
X-NewRelic-App-Data
X-Info
ServerHost
X-Dynatrace-Js-Agent
CDN
X-Webkit-Csp-Report-Only
X-Hit
Request-ID
Ngx-Var-Key
X-Response-Served-From
CacheControlHeader
X-Original-Request-Id
X-WA
Xc-Version
X-Cdn-Forward
X-Vc
X-Vgn-Hpd-Reason
Expect-Staple
X-APP-VERSION
Server-Id
X-Moov-Xdn-Version
X-Moov-T
X-COUNTRY
Hostname
X-FL-QIT-DEBUG
Srvid
X-Amz-Meta-Opti
Cneonction
X-NC
X-TH-Server
X-Presslabs-Stats
Cf-Ipcountry
X-V
X-Geo
X-Lb-Nocache
X-Dispatch
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
PICS-Label
X-Platform-Server
X-ServedByHost
Geoip-Latitude
X-Rollout
Cloudfront-Viewer-Country
X-New
X-Eligible
Cf-Device-Type
X-VCL-Version
X-Oracle-DMS-ECID
Origin-Trial
X-Application
N-Cache
X-Via-PopV
X-Via-PopN
Permission-Policy
WZWS-RAY
X-S-Cookie
X-External-Request-Id
X-Destination
X-Via-PopH
X-Limited
X-Proxy-CacheRZ
XkeyRZ
X-B-Cookie
Cross-Origin-Embedder-Policy-Report-Only
X-User
X-Ha-Backend
Ohc-File-Size
X-Ftr-Request-Id
X-ElasticPress-Query
X-Internal-TTL
X-Akamai-Pragma-Client-IP
X-Zen-Fury
X-App
X-Correlation-ID
X-Ua
Rtss
Cl-Cache
Edge-Copy-Time
X-MSEdge-Features
X-Sqd-Ctime
X-Sigma
X-Sqd-Stime
Epwk-X-Cache
X-MiniProfiler-Ids
X-Sigma-Backend
X-Lb-Id
X-MSEdge-Flight
X-Via-SSL
X-Cache-Date
X-Check-Cacheable
X-Serial
X-Litespeed-Cache-Control
X-Rocket-Build-Number
X-Instance-Name
X-VTEX-Cache-Backend-Connect-Time
X-EC-Lua
X-Path
X-VTEX-Cache-Backend-Header-Time
X-Via-CDN
X-Via-Edge
Lb
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Timeexpire
X-Datacenter
X-Segment-20210421
X-VServer
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Branch-Name
X-SIPLIST1
X-Web-Server
Sm-Log-Id
X-Service-Response-Time
X-Acquia-Site
X-Acquia-Purge-Tags
Cmstype
X-API-Version
IsBot
Cmsid
X-CDN-Origin
X-CSRF-TOKEN
Servername
X-LAGOON
CountryCode
X-Traceid
X-Irp-Debug
X-DynaTrace
Fl-Custom-Application
X-Shopid
X-RAMCache
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-Th-Server
X-Ramcache
Warning
Ngx
X-Snapshot-Date
X-Dw-Trace-Id
X-IN-APIGATEWAY
Ohc-Cache-HIT
Wpo-Cache-Message
Wpo-Cache-Status
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-IN-APIGATEWAYSSL
X-Origin-Upstream-Status
X-Shardid
X-Fastly-Backend-Reqs