Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Check
X-Drupal-Cache
X-Generator
X-Ua-Compatible
X-Cache-Status
Server-Timing
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
Cf-Edge-Cache
X-Amz-Id-2
X-Via
Host-Header
Permissions-Policy
EagleId
Keep-Alive
Request-Context
X-Cache-Group
X-Robots-Tag
X-Backend
X-UA-Device
X-AH-Environment
X-Hacker
X-Proxy-Cache
X-Server
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
Xkey
X-Dispatcher
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Server-Powered-By
X-LiteSpeed-Cache
Ali-Swift-Global-Savetime
Allow
X-Varnish-Cache
X-OneAgent-JS-Injection
P3p
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Cache-Lookup
X-WebKit-CSP
EagleEye-TraceId
X-Host
X-Backend-Server
Cf-Railgun
X-Server-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
Surrogate-Control
X-Ruxit-JS-Agent
X-Akam-SW-Version
X-HW
X-Node
Request-Id
X-Cloud-Trace-Context
X-Country
Content-Location
X-Nginx-Cache-Status
X-Application-Context
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Litespeed-Cache
X-Country-Code
X-ASPNET-VERSION
Service-Worker-Allowed
X-Content-Type
X-Trace
Cache-Tag
X-Url
X-Clacks-Overhead
X-Amz-Server-Side-Encryption
Rating
X-Times
X-Rack-Cache
X-Vname
X-TtlSet
X-PC
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Daa-Tunnel
Nginx-Cache
X-Server-Name
AR-PoweredBy
AR-Request-ID
AR-SID
AR-ATIME
X-Powered-By-Plesk
X-Cache-TTL
X-Cnection
Accept-Ch
X-FTR-Request-ID
X-Ac
X-ESI
X-GitHub-Request-Id
X-D2id
X-Element-Page-Cache
X-Kinja
X-Kinja-Server
X-Cdn-Fetch
X-CST
X-Kinja-Build
X-GoogleNews-Bot
Verso
X-Kinja-Revision
X-Exp-Variant
X-Exp-Id
Edge-Control
X-MS-InvokeApp
AR-CACHE
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Upstream
X-Dw-Request-Base-Id
X-Navigation-Version
X-FastCGI-Cache
X-B3-TraceId
Fastly-Restarts
X-ECACHE
SPRequestDuration
SPIisLatency
X-Webkit-Csp
X-Mod-Pagespeed
X-Amz-Rid
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-SharePointHealthScore
SPRequestGuid
X-ARC
X-Goog-Hash
X-Edge-Location-Klb
X-Kinsta-Cache
X-Client-IP
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Powered-CMS
X-Ratelimit-Limit
X-Mg-S
X-Oneagent-Js-Injection
Edge-Cache-Tag
X-Amzn-Trace-Id
S
Cache-Status
X-Version
Access-Control-Request-Method
Response
X-Middleton-Response
X-VARITI-CCR
X-NF-Request-ID
RTSS
Realpath
X-Forwarded-For
X-Ratelimit-Remaining
X-Cache-Key
X-TTL
X-T
Cross-Origin-Resource-Policy
X-Content-Digest
X-Recruiting
X-ORACLE-DMS-RID
X-Correlation-Id
Fastcgi-Cache
X-Cached
X-Fastly-Request-ID
X-MSEdge-Ref
X-Shield-Request-Id
X-TraceId
X-Varnish-TTL
Front-End-Https
MicrosoftSharePointTeamServices
X-SRCache-Store-Status
X-Ua-Browser
X-PressLabs-Stats
X-SRCache-Fetch-Status
X-Request-Processing-Time
X-Request-Received
X-Forwarded-Proto
Arr-Disable-Session-Affinity
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
TP-Cache
Payment
Server-Node
X-Protected-By
X-Frontend
X-LLID
Public-Key-Pins
X-RateLimit-Remaining
MS-Author-Via
Count-Hit
X-Ruxit-Js-Agent
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Content-MD5
X-HS-Combine-CSS
X-LB-Cache
X-Accel-Expires
X-GUploader-UploadID
X-Distributor
X-Origin-Server
X-Server-ID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Newrelic-App-Data
X-ORACLE-DMS-ECID
Surrogate-Key
X-Ezoic-Cdn
X-NODE
X-Request-Handler-Origin-Region
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Microsite
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Content-Security-Policy-Report-Only
X-Country-Code-Real
X-FTR-Backend
X-Www-Served-By
X-Activity-Id
Host
X-App-Server
X-AppVersion
X-Az
X-Varnish-Server
Accept-Charset
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Amz-Meta-S3cmd-Attrs
X-Cluster-Name
Cleartype
Cache-Tags
X-Varnish-Backend
Retry-After
X-FTR-Expires
Filterid
X-Goog-Metageneration
X-Unique-Id
X-Ua-Device
X-Debug
X-Ttl
Server-Name
X-Git-Hash
Access-Control-Allow-Method
X-Hits
X-Logged-In
X-Load-Cache
X-Id
X-Aspnet-Version
X-Azure-Ref
X-Upgrade-Enabled
X-Envoy-Decorator-Operation
X-NGENIX-Cache
X-Geo-Country
X-CSRF-Token
X-FB-Debug
X-Hostname
TCN
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-B
Section-Io-Cache
X-TT
X-Proxy
TP-L2-Cache
Viewport
X-Revision
X-Request-Guid
X-Seen-By
DC
X-Trace-Id
Healthy
X-Cache-Control
X-Fb-Rlafr
X-Contextid
X-B3-Sampled
X-Type
X-Grace
X-Time
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Goog-Generation
X-F-Cache
X-Goog-Stored-Content-Length
X-Varnish-Ttl
Fastly-SIE
Fastly-SWR
X-N
X-Mobile
Content-Disposition
X-XRDS-LOCATION
X-Ratelimit-Reset
Paypal-Debug-Id
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Referer-Policy
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Varnish-Grace
X-Amz-Replication-Status
X-Nf-Request-Id
X-Origin-Cache
X-Magnolia-Registration
X-Via-JSL
X-DIS-Request-ID
X-Debug-Info
X-Page-Id
X-Webkit-CSP
X-Wormhole-Sdk
X-Px
Version
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-ProcessESI
X-RemovedCookies
X-G
X-UUID
X-Whom
X-Tumblr-Pixel-1
X-Oracle-Dms-Ecid
X-Tumblr-Pixel-0
X-Adobe-Content
X-Adobe-Loc
X-Tumblr-User
X-App-Environment
X-Content-Options
X-Rule
X-Debug-IsPreview
X-Debug-IsConnected
X-Node-Name
X-Tumblr-Pixel
X-Datadog-Sampled
X-Yottaa-Metrics
VIX-Pulpo-Upstream-Status
X-Ismobilevalue
X-Source
MS-CV
Ms-Operation-Id
SD-X-WS
NGB
VIX-Pulpo-Node
X-Yottaa-Optimizations
X-RTag
X-Storage
X-Template
X-Hl-Ver
X-Device-Type
X-Instance
X-Is-Bot
X-NYM-Debug-Backend
X-Signature
X-B-Cache
X-Backend-Name
X-Proxy-Cache-Info
X-Cacheable-TTL
X-Wix-Request-Id
X-Rendered-As
X-Region
X-ServerID
Country
X-L-Path
X-Status
X-FW-Server
GEO-INFO
X-User-Agent
Cross-Origin-Window-Policy
X-Environment-Context
X-FW-Dynamic
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Type
X-FW-Version
Amp-Access-Control-Allow-Source-Origin
X-Rid
Charset
Countrycode
X-EdgeConnect-Cache-Status
X-NWS-UUID-VERIFY
Akamai-GRN
ServerID
Front
X-IPS-LoggedIn
X-RM-Cache-TTL
X-URL
X-Real-IP
X-Cache-Age
X-Framework
X-WP-CF-Super-Cache-Active
X-Cache-Grace
SRV
X-B3-SpanId
Liferay-Portal
X-Amzn-Remapped-Content-Length
X-AB
X-Cache-Hit
X-Language
X-WebKit-CSP-Report-Only
X-ECache
X-Air-Pt
X-Content-Powered-By
X-Akamai-Request-ID2
X-Oracle-Dms-Rid
X-Api-Version
OT-Force-Account-Verify
X-Fastly-Request-Id
X-Air-Hostname
X-Servername
X-Air-Trace-Id
X-Air-Source
Xet-Cookie
X-UA
X-Sucuri-Cache
X-Sucuri-ID
X-DataDome
Accept-Language
X-VC-Cache
From-Origin
X-Mode
X-SRV
Backend
X-VC
Refresh
X-Cache-Status-Check
Access-Control-Request-Headers
X-HTML-Minification-Powered-By
X-Xrds-Location
LB
Upgrade-Insecure-Requests
X-Aws-Lambda-Call-Status
X-Handled-By
X-Cache-Time
X-Tt-Logid
X-SaId
Meta-Geo
X-RID
X-Rn-Rsrv
X-Rewrite-Enabled
X-JoinUs
Filters
X-UPSTREAM-Address
X-Mg-Request-UUID
Webserver
X-RCS-CacheZone
X-Generated-By
X-Cms-Context
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
X-PHP-Host
X-Adobe-Source
TWC-Locale-Group
Webcakes-Region
X-Hosted-By
X-Nginx-Cache
X-Labrador-Cache-Channel
X-Provided-By
X-R9-Blue-Green-Version
X-Origin-Date
X-Origin-Hint
Property-Id
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
X-Webstats-RespID
X-Request-URI
X-S
X-Container-Uri
X-Tumblr-Pixel-2
X-Varnish-Age
X-Git-Commit
Section-Io-Id
ServedBy
X-Is-Supported-Browser
X-Is-Tablet
X-Vcl-Version
X-Locale
X-No-Session
X-ProxyCache-Key
X-Loop
X-Logging-Id
X-Lambda-Id
X-Is-Mobile
X-Tncms
X-Scope-Id
X-Browser-Name
X-Tcp-Rtt
X-BYPASS-REASON
X-Cache-Debug
X-Geo-Region
X-Httpd
X-Accel-Version
X-Tb
X-Served-From
X-ProxyCache-Status
X-Site-Version
X-Skip-Cache
Web-Mar-Node
Url
X-Is-Desktop
Atl-Traceid
X-Forwarded-Host
X-Web-Node
X-Xfnlog-Site
X-Redis-Cache
X-Reqid
Cache
X-Soup
X-Alternate-Cache-Key
X-Optimistic-Header
X-Origin
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-IPLB-Request-ID
X-Say-Cacheable
X-SayCDN-TTL
Selected-Fe
X-Timing-Wait
X-Format
X-Say-TTL
X-Cache-Host
X-Upstream-Ht
X-Detected-As
X-Restarts
X-Shopify-Stage
X-Proxy-Build
X-Director
X-Frame-Option
X-Fetched-On
X-VCT
X-Cluster
Mn-Server-Ip
X-Akamai-Edgescape
Apigw-Requestid
X-Storefront-Renderer-Rendered
X-Upstream-Ct
X-IPLB-Instance
X-Zipkin-Id
X-Cache-Operation
X-Cloudmap
X-Extlb
X-Cache-Rule
Onion-Location
Xserver
X-Proxied
X-RateLimit-Limit
X-Routing-Service
X-ShopId
X-AWS-Id
X-Sorting-Hat-PodId
X-ShardId
Expiry
X-Endurance-Cache-Level
X-Connection-Hash
X-Sorting-Hat-ShopId
X-LJ-Flow-ID
X-Edge-Location
X-VWS-Id
X-INCAP-ABP
X-Lagoon
X-Ms-Request-Id
X-Vcache
Priority
Frame-Options
X-Ms-Version
X-GeoCode
X-Cache-Expired-At
X-Azure-Ref-OriginShield
X-GeoCountry
Source
X-CDN-Forward
X-WP-CF-Super-Cache-Cookies-Bypass
Protected
Cdn-Requestid
Environment
WPO-Cache-Status
WPO-Cache-Message
X-Generation-Time
X-Cache-Action
X-Proxy-Cache-Status
X-Shield-Cache-Expires
X-Thinkindot-L3
Fastcgi-Useragent
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-CMSURLCustom
TDXMobile
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
Uber-Trace-Id
CF-IPCountry
X-XRDS-Location
X-Origin-CC
X-PHP-Backend
X-Cdn-Origin
X-Origin-TTL
X-Pass-Why
X-GEO
X-Worker
X-App-Version
X-Rocket-Nginx-Serving-Static
X-Cluster-Node
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-ID
X-Client-Ip
Sid
Azure-Version
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-SlotName
X-Buckets
Node
Cache-Tv-Group
X-Vercel-Id
X-Aspnetmvc-Version
X-Vercel-Cache
X-FB-TRIP-ID
Cache-Hits
X-Auth-Group-Type
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-Uid
CDN-Cache
CDN-PullZone
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-CachedAt
X-Tumblr-Pixel-3
Cross-Origin-Embedder-Policy
AMP-Access-Control-Allow-Source-Origin
X-Fastcgi-Cache
X-TA-CDN-Provider
X-Server-W
X-HITS
Alternate-Protocol
X-B3-Traceid
X-Cache-Server
X-Pad
X-A
DB-Nickname
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-A-Ccd
X-A-Dam
DCR-Processing-Time-Ms
Content-Secure-Policy
DCR-Decision-By
Gannett-Cam-Experience-Id
Cdn-Request-Time
Cdn-Host
X-LSADC-Cache
A
Candidate-Md5Url
Lang
Magicmarker
Rendered-Blocks
Sslversion
Surrogated-Key
Origin-Agent-Cluster
Odigeo-Trace-Id
MD5-Digest
Meta-Geo-Continent
Ngx.Var.Host
T-Server
X-Conf
X-Op-Id-All
X-Org
X-Origin-Expires
X-Req
X-ND-Cache
X-Level-Front-Cache
X-GeoIP-City
X-Gzip
X-Ig-Origin-Region
X-Ig-Push-State
X-Rojux
X-ScT
X-Vdms-Version
X-Via-Fastly
X-Viewer-Country
X-Vtex-Remote-Cache
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-SRCache-Key
X-TIM-N
X-V-Cache
X-Varnish-CookieHashed-On
X-Generated-On
X-Fastly-Backend
X-Cache-Id
X-Cache-NE
X-Cache-TTL-Remaining
X-Content-Age
X-Bl-Debug
X-BCube-Filmed-By
X-A-Dgt
X-A-Wwc
X-Aed
X-Bc-Bl
X-Core-Value
X-D
X-Ec-GeoHdr
X-Edge-Server
X-Epic-Correlation-Id
X-Esi-Check
X-Ec-Fail
X-Dispatcher-Server
X-DefElseHash
X-DefHash
X-Developer
X-A-Dcw
X-Custom-Header
X-LiteSpeed-Cache-Control
X-Service
User-Cache-Control
X-DC
X-Tx-Id
Mime-Version
X-Fmm-Version
X-Clientip
X-NGINX-Cache
X-CacheTTL
X-Cache-Info
X-Forwarded-Site
X-Cache-FS-Status
X-VTEX-Cache-Time
X-Debug-Cache-Fetch
X-HN
X-Thanos
X-DPWN-IS-SECURE
X-Debug-Cache-Store
X-NodeID
X-FC-Vary-Parameters
X-Fastly-Cache
X-UA-Device-Type
X-Block-Status
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Tube-Return
X-VTEX-Cache-Server
Ssr
RNT-Machine
RNT-Time
Server-Host
V-Age
Vix-Hermes-Req-Id
X-Backend-Instance
X-Bip
X-VarnishDD-TTL
X-Gdpr
X-App-Name
X-Amz-Storage-Class
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-AK-Request-ID
X-Cache-Bucket
X-Geo-Header
X-RateLimit-Remaining-Second
X-Region-Sid
Cache-Provider
X-Request-Time
X-RateLimit-Limit-Second
X-Pubstack
X-Policy
X-Powered-By-VTEX-Cache
X-Proto
X-SB
X-Scheme
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Tb-Optimization-Total-Bytes-Saved
X-Sn-Servicetimems
X-Wikidot-Backend
X-SD-PageType
X-Wikidot-Static-Cache
X-Server-IP
X-Platform
X-PAYTM-SRV-ID
X-HS-Content-Campaign-Id
X-Dc
PFcat
X-Jobs
X-Hnp-Log
X-GoCache-CacheStatus
Req-ID
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Loc
X-Men
Fastly-SSL
X-Origin-Response-Time
X-Origin-Time
X-Nyt-Route
X-Node-Id
X-Micro-Cache
X-Mly-Id
X-Mvc-Supplant-Cachable
X-Gen-Mode
X-B3-Trace-ID
Platform
Powered-By
Producers
X-Varnish-Director
X-Varnish-Hostname
Content-Style-Type
AKAMAI
Country-Code
Adler-Geo
Edge-Cache
Cdncip
X-VG-TLSProxy
X-VG-WebCache
Click-Count-Error
Host-ID
Is-Eu
Fastly-Backend-Name
Content-Script-Type
Click-Count-Action-Start
Cdnsip
W
X-Access
X-GeoIP
X-Varnishpool
True-Client-Country-4JS
X-Ec-Custom-Error
X-Date
Fastly-GeoIP-CountryCode
X-CUA
Gh-Request-Id
X-Contensis-Viewer-Groups
X-Depends
X-Eu-Site
Req-Svc-Chain
DSUID
Cluster
Esi-Enabled
X-CGP
L
X-Request-Start
Apple-News-Services-Request-Url
X-Request-Host
HostName
X-Proxied-Request
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-We-Are-Hiring
Yak-Timeinfo
Apple-News-Services-Handled
X-Pool
CDCHOST
Canary
X-Mvc-Supplant-OutputCached
X-Location
X-Cdn-Srv
L5d-Success-Class
HA-Ipaddr
Cache-Key
Ha-Gx-Prefs
C-Via
X-NMSegId
X-Nginx-Cache-Key
X-Human
X-Csrf-Jwt
NM-Fastcgi-Cache
X-Varnish-Authentication
X-Accel-Expires-Debug
X-Varnish-Beresp-Status
Server-Info
X-Auto-Login
XM
X-BBC-Edge-Cache-Status
X-Test
X-Var-Ttl
Web-Mar-Region
We-Hiring
Sever-Int
Server-Hostname
Server-Ext
Release
Proxy-Firewall
Pramga
Origin
Origin-CC
Origin-EX
NGX
On-Server
X-Cache-Aspx
Machine
X-Section
Mail-Subject
X-Varnish-Beresp-Ttl
X-Hash
X-Cs
BehaviorPad-Version
Debug
X-AIR-PT
X-RateLimit-Reset
Fusion-Template-Id
X-Ad-Load-Variation
Fusion-Source
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Component-Id
X-WA-Info
Fusion-Content-Source
X-Device-Os
X-Varnish-Hits
X-APP
X-LB-ID
Redirect-Candidate
X-Zone
X-Newrelic-Synthetics
X-MP-GENERATED-AT
X-CACHE-AGE
X-Via-Poph
X-Via-Popv
X-CLOUD-TRACE-CONTEXT
X-Via-Popn
X-HA-Backend
SID
CDN-RequestId
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
GeoIP-Latitude
Pics-Label
X-From
X-Content-Length
X-NCache
X-Up
Fastly-Drupal-HTML
X-LiteSpeed-Tag
X-B3-Parentspanid
X-VHOST
X-Akamai-Transformed
CloudFront-Viewer-Country
X-Jungle-Id
X-Refresh
X-Vdms-Path
X-Servedbyhost
X-Nananana
X-Cache-Backend
Vc-Max-Age
X-Parent-Response-Time
Fastly-Drupal-Html
X-SERVER-NAME
X-Origin-Cache-Key
X-Litespeed-Tag
X-Nc
X-LB-NoCache
X-Dispatcher-Number
WP-Super-Cache
X-CDN-Cache-Status
X-RequestId
X-Datadome
X-ZONE
X-Cached-By
Product
X-Uri
X-CACHE-KEY
X-DynaTrace-JS-Agent
Datacenter
X-Render-Time
Server-ID
X-M-Log
X-Wa
X-PERF
X-ApacheServer
X-VC-TTL
Resin-Trace
X-M-Reqid
X-CS
X-Ckpd-Fst-Backend
X-Amz-Meta-Cb-Modifiedtime
Cdn
NtCoent-Length
GeoIp-Country-Code
S-Rt
X-B3-Spanid
X-Varnish-Beresp-TTL
X-Bug-Bounty
X-NewRelic-App-Data
X-IAuth-Set-Uid
Uri
ServerName
FSS-Cache
X-Fpc
Locid
X-TX-ID
X-TT-LOGID
X-HubSpot-Correlation-Id
X-Esi
Serverhost
X-VCache
True-Client-IP
X-HostName
X-Nf-Country
X-Nf-Language
X-Nf-Ats-Version
Srv
True-Client-Ip
X-Vmg-Version
X-Akamai-Device-Characteristics
User-Agent
X-Dynatrace-Js-Agent
X-Old-Content-Length
X-Vc
Tcn
X-Original-Request-Id
X-Response-Served-From
CDN
X-FPC
X-TIME
X-Srv
ServerHost
X-Info
X-Gamma-Serve
GeoIP-Country-Code
Ngx-Var-Key
X-WA
Request-ID
X-Hit
X-Cdn-Forward
X-Cdn-Cache-Status
Server-Id
CacheControlHeader
X-Vgn-Hpd-Reason
X-APP-VERSION
Xc-Version
Hostname
Cf-Ipcountry
X-TH-Server
X-Moov-T
X-NC
Expect-Staple
X-Moov-Xdn-Version
X-COUNTRY
X-Lb-Nocache
X-Webkit-Csp-Report-Only
X-Platform-Processor
X-Amz-Meta-Opti
Srvid
Cneonction
X-Platform-Router
X-Dispatch
X-FL-QIT-DEBUG
X-Platform-Cluster
X-Presslabs-Stats
X-V
X-ServedByHost
Geoip-Latitude
X-Geo
Cf-Device-Type
Cloudfront-Viewer-Country
WZWS-RAY
Cross-Origin-Embedder-Policy-Report-Only
Permission-Policy
X-Platform-Server
X-Eligible
X-Rollout
X-New
N-Cache
X-B-Cookie
X-Application
PICS-Label
X-External-Request-Id
X-S-Cookie
X-User
X-Destination
X-VCL-Version
X-Oracle-DMS-ECID
Origin-Trial
X-Via-PopN
X-Zen-Fury
XkeyRZ
X-Limited
X-Ha-Backend
X-Proxy-CacheRZ
X-Via-PopH
X-Via-PopV
X-Sigma
X-ElasticPress-Query
X-Sigma-Backend
X-Ftr-Request-Id
X-Internal-TTL
Ohc-File-Size
X-Akamai-Pragma-Client-IP
Epwk-X-Cache
X-Ua
X-Rocket-Build-Number
X-App
X-Correlation-ID
X-Cache-Date
X-Instance-Name
Rtss
X-Sqd-Stime
X-Via-Edge
X-Sqd-Ctime
X-Litespeed-Cache-Control
X-VTEX-Cache-Backend-Connect-Time
X-VServer
X-VTEX-Cache-Backend-Header-Time
Edge-Copy-Time
X-Segment-20210421
X-Via-CDN
X-Branch-Name
X-Check-Cacheable
X-Path
X-Via-SSL
X-API-Version
X-EC-Lua
X-MSEdge-Flight
X-Lb-Id
Cl-Cache
X-Serial
X-MiniProfiler-Ids
X-MSEdge-Features
X-Wp-Cf-Super-Cache
Lb
X-Wp-Cf-Super-Cache-Cache-Control
Timeexpire
WebServer
Sm-Log-Id
X-Service-Response-Time
IsBot
X-SIPLIST1
X-Datacenter
X-Web-Server
X-Acquia-Application-Trace
Cmsid
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Cmstype
X-LAGOON
Servername
CountryCode
X-CDN-Origin
X-CSRF-TOKEN
X-Amz-Meta-S3b-Last-Modified
Warning
Ngx
X-Snapshot-Date
X-Irp-Debug
X-Traceid
X-DynaTrace
X-RAMCache
X-Ramcache
X-Th-Server
X-Amz-Meta-Sha256
X-Dw-Trace-Id
X-Sorting-Hat-Podid
X-Fastly-Backend-Reqs
X-Sorting-Hat-Shopid
Wpo-Cache-Status
Wpo-Cache-Message
X-Shopid
X-Shardid
Fl-Custom-Application
Ohc-Cache-HIT
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Origin-Upstream-Status
X-Udemy-Cache-App-Namespace