Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Request-ID
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
CF-Ray
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-UA-Device
X-Cache-Group
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
Permissions-Policy
X-Age
X-Vhost
X-Amz-Version-Id
Allow
X-Dispatcher
X-Dns-Prefetch-Control
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-Host
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Litespeed-Cache
X-Cloud-Trace-Context
Content-Location
X-Application-Context
X-Node
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-Ruxit-JS-Agent
X-CST
X-NWS-LOG-UUID
X-Country
Service-Worker-Allowed
X-Country-Code
X-Content-Type
X-Url
X-Clacks-Overhead
Cache-Tag
X-Trace
Rating
X-Rack-Cache
X-Oneagent-Js-Injection
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Server-Name
X-FTR-Request-ID
X-Times
X-PC
X-Vname
X-TtlSet
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Webkit-Csp
X-Powered-By-Plesk
X-ESI
X-Cnection
X-ECACHE
X-Upstream
X-MS-InvokeApp
Edge-Control
X-GitHub-Request-Id
X-D2id
X-Element-Page-Cache
Verso
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Ac
AR-Request-ID
AR-SID
AR-PoweredBy
AR-ATIME
X-FastCGI-Cache
X-Aws-Lambda-Call-Status
X-Ser
X-Vcap-Request-Id
X-Ruxit-Js-Agent
Accept-Ch-Lifetime
X-Cache-TTL
X-Navigation-Version
X-Abt-Application-Version
X-Mod-Pagespeed
AR-CACHE
SPIisLatency
SPRequestDuration
X-Dw-Request-Base-Id
X-SharePointHealthScore
X-B3-TraceId
SPRequestGuid
X-NF-Request-ID
Fastly-Restarts
X-Amz-Rid
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Middleton-Display
Pagespeed
Display
X-Sol
X-Client-IP
Edge-Cache-Tag
X-Mg-S
S
X-Edge-Location-Klb
X-Kinsta-Cache
X-Powered-CMS
X-Middleton-Response
Response
X-Amzn-Trace-Id
Cache-Status
X-Cache-Key
Access-Control-Request-Method
X-Goog-Hash
X-VARITI-CCR
X-Version
X-RateLimit-Remaining
X-Fastly-Request-ID
X-ARC
RTSS
X-Content-Digest
X-TraceId
X-Forwarded-For
Cross-Origin-Resource-Policy
X-Recruiting
X-T
Realpath
X-Ratelimit-Limit
X-MSEdge-Ref
X-Varnish-TTL
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Front-End-Https
MS-Author-Via
Fastcgi-Cache
X-Correlation-Id
X-Cached
Content-MD5
X-HS-Cache-Config
X-HS-Hub-Id
X-Ttl
X-HS-Content-Id
X-PDP-UNCACHING-HASH
X-Ua-Browser
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
Server-Node
Payment
X-FTR-Cache-Status
X-Request-Received
MicrosoftSharePointTeamServices
X-Protected-By
Public-Key-Pins
X-Request-Processing-Time
X-Shield-Request-Id
Arr-Disable-Session-Affinity
X-HS-Combine-CSS
X-Forwarded-Proto
X-LLID
X-Frontend
TP-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Distributor
X-FTR-Expires
X-Accel-Expires
X-HP-Webp
X-Ratelimit-Remaining
X-HP-Trace-Id
X-Jurisdiction
X-Origin-Cache-Key
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-TTL
Count-Hit
X-Server-ID
X-Origin-Server
X-LB-Cache
X-NODE
X-Ezoic-Cdn
X-ORACLE-DMS-RID
X-Hits
X-GUploader-UploadID
X-Microsite
X-Content-Security-Policy-Report-Only
X-Request-Handler-Origin-Region
X-Activity-Id
X-PressLabs-Stats
X-Az
X-AppVersion
Host
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Www-Served-By
X-Varnish-Backend
X-Cluster-Name
X-Varnish-Server
Retry-After
Cache-Tags
X-App-Server
X-Amz-Meta-S3cmd-Attrs
Accept-Charset
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Ua-Device
Server-Name
X-Hostname
X-Webkit-CSP
X-Geo-Country
Cleartype
X-NGENIX-Cache
X-Envoy-Decorator-Operation
X-Newrelic-App-Data
X-Id
X-Goog-Metageneration
Referer-Policy
X-DIS-Request-ID
TP-L2-Cache
X-Upgrade-Enabled
Access-Control-Allow-Method
X-CSRF-Token
X-Azure-Ref
X-Seen-By
TCN
X-Git-Hash
X-Load-Cache
X-F-Cache
X-CCDN-CacheTTL
X-Amz-Apigw-Id
X-Amzn-RequestId
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-ORACLE-DMS-ECID
X-Unique-Id
X-Proxy
X-Tt-Trace-Tag
X-Tt-Trace-Host
Filterid
X-Oracle-Dms-Ecid
X-RateLimit-Limit
Healthy
X-Grace
X-Trace-Id
X-Revision
X-Cache-Control
Section-Io-Cache
X-Request-Guid
X-Debug-Info
X-Px
X-FB-Debug
Paypal-Debug-Id
X-B3-Sampled
X-TT
X-B
DC
X-Fb-Rlafr
X-Type
X-Contextid
X-Page-Id
X-Varnish-Ttl
X-Logged-In
X-N
X-Mobile
X-Oracle-Dms-Rid
Viewport
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Debug
X-Whom
X-Language
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-XRDS-LOCATION
Charset
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Template
Fastly-SIE
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
Fastly-SWR
X-Content-Options
X-Cache-Grace
Version
Content-Disposition
X-Via-JSL
X-Magnolia-Registration
X-Time
X-EdgeConnect-Cache-Status
X-Varnish-Grace
X-Wix-Request-Id
X-B-Cache
X-Signature
X-App-Environment
X-Node-Name
X-RateLimit-Reset
X-Rid
X-Origin-Cache
SRV
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-RemovedCookies
X-ProcessESI
X-Yottaa-Optimizations
X-Datadog-Sampled
X-Yottaa-Metrics
X-Debug-IsConnected
X-Tumblr-Pixel
X-Tumblr-User
X-Debug-IsPreview
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
Ms-Operation-Id
X-Hl-Ver
X-Amz-Replication-Status
X-UUID
X-Amzn-Remapped-Content-Length
SD-X-WS
X-Backend-Name
X-G
X-Rule
X-RTag
MS-CV
X-Device-Type
X-Adobe-Loc
X-FW-Static
X-Instance
X-FW-Server
X-FW-Type
GEO-INFO
X-FW-Version
X-Adobe-Content
X-FW-Serve
X-FW-Dynamic
X-Proxy-Cache-Info
X-Storage
X-FW-Hash
Country
Liferay-Portal
ServerID
X-Is-Bot
X-Cacheable-TTL
X-Rendered-As
X-NYM-Debug-Backend
X-B3-SpanId
NGB
X-Status
X-Environment-Context
X-Cache-Hit
X-Region
X-User-Agent
X-IPS-LoggedIn
X-L-Path
X-Source
X-Real-IP
X-Cache-Age
Surrogate-Key
X-NWS-UUID-VERIFY
Countrycode
X-ServerID
Amp-Access-Control-Allow-Source-Origin
Akamai-GRN
X-Servername
X-Sucuri-Cache
X-Sucuri-ID
Cross-Origin-Window-Policy
OT-Force-Account-Verify
X-WP-CF-Super-Cache-Active
From-Origin
X-VC-Cache
X-WebKit-CSP-Report-Only
X-UA
X-Xrds-Location
X-RM-Cache-TTL
Upgrade-Insecure-Requests
Backend
Front
X-Framework
X-INCAP-ABP
X-Air-Pt
X-Mode
Refresh
X-AB
Frame-Options
X-Content-Powered-By
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Cache-Time
X-Akamai-Request-ID2
X-HTML-Minification-Powered-By
X-Handled-By
X-Nginx-Cache
Xet-Cookie
X-Wormhole-Sdk
Url
X-Edge-Location
X-Endurance-Cache-Level
X-DataDome
X-Buckets
X-Vcache
X-Webstats-RespID
X-JoinUs
Access-Control-Request-Headers
X-B3-Traceid
Selected-Fe
X-UPSTREAM-Address
X-Timing-Wait
X-SaId
X-Cluster
Filters
X-Xfnlog-Site
Meta-Geo
X-Rn-Rsrv
X-Reqid
X-Origin-Date
X-Rewrite-Enabled
X-Proxy-Build
X-No-Session
Webserver
X-RCS-CacheZone
X-VCT
X-LJ-Flow-ID
X-Origin
Webcakes-App-Name
Webcakes-App-Version
TWC-Privacy
X-Origin-TTL
X-R9-Blue-Green-Version
X-Tumblr-Pixel-2
X-Drupal-Cache-Tags
X-Origin-CC
X-Akamai-Edgescape
TWC-Device-Class
ServedBy
Webcakes-Region
X-Azure-Ref-OriginShield
TWC-GeoIP-LatLong
X-VWS-Id
X-Served-From
X-Origin-Hint
TWC-GeoIP-Country
TWC-Connection-Speed
WPO-Cache-Message
Property-Id
X-Cache-Rule
X-Cache-Operation
TWC-Locale-Group
X-AWS-Id
WPO-Cache-Status
X-Varnish-Cache-Hits
X-Adobe-Source
Cache
X-Accel-Version
Web-Mar-Node
X-BYPASS-REASON
Mn-Server-Ip
X-Cache-Debug
Section-Io-Id
TDXMobile
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Cloudmap
X-Cms-Context
X-Generation-Time
Atl-Traceid
X-Git-Commit
X-Fetched-On
X-Extlb
X-CMSURLCustom
X-Container-Uri
X-Drupal-Cache-Contexts
X-Httpd
X-Web-Node
X-Shield-Cache-Expires
X-Scope-Id
X-Site-Version
X-Ms-Version
X-Logging-Id
X-Ms-Request-Id
X-Routing-Service
X-CDN-Forward
X-Proxied
X-PHP-Host
X-ProxyCache-Key
X-ProxyCache-Status
X-Restarts
X-Redis-Cache
X-Locale
X-Thinkindot-L3
X-VC
X-Zipkin-Id
X-Cache-Status-Check
X-Labrador-Cache-Channel
X-Director
X-Say-TTL
X-S
X-Tcp-Rtt
X-Say-Cacheable
X-Tb
X-Browser-Name
X-Skip-Cache
X-Loop
X-Lambda-Id
X-SayCDN-TTL
X-Soup
X-Format
X-Forwarded-Host
X-Tncms
X-Upstream-Ct
X-Is-Mobile
X-Hosted-By
X-Is-Desktop
X-Is-Supported-Browser
Accept-Language
X-Is-Tablet
X-Frame-Option
X-Upstream-Ht
X-Varnish-Age
Apigw-Requestid
X-Geo-Region
X-Shopify-Stage
X-ShardId
X-Alternate-Cache-Key
X-ShopId
X-Provided-By
X-Sorting-Hat-ShopId
Cache-Hits
X-Detected-As
X-IPLB-Request-ID
X-SRV
X-Varnish-Beresp-Grace
X-GeoCountry
X-GeoCode
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-IPLB-Instance
X-Cache-Host
X-Cdn-Origin
Xserver
X-Generated-By
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-RID
X-Worker
X-Optimistic-Header
X-Rocket-Nginx-Serving-Static
X-Vercel-Id
X-Vercel-Cache
Source
Azure-SlotName
Azure-SiteName
Azure-Version
X-XRDS-Location
Azure-RegionName
Azure-InstanceId
LB
X-Lagoon
Node
X-Request-URI
CDN-EdgeStorageId
X-Tec-Api-Origin
X-Tec-Api-Version
CDN-Cache
X-WP-CF-Super-Cache-Cookies-Bypass
X-Tec-Api-Root
X-App-Version
CDN-PullZone
CDN-CachedAt
CDN-RequestCountryCode
Protected
CDN-Uid
CDN-RequestPullCode
CDN-RequestPullSuccess
Fastcgi-Useragent
X-Pass-Why
Cross-Origin-Embedder-Policy
X-Vcl-Version
CDN-RequestId
X-Ratelimit-Reset
X-Tumblr-Pixel-3
X-Connection-Hash
Expiry
X-URL
X-GEO
Alternate-Protocol
Onion-Location
X-Cache-Server
X-Cache-Expired-At
X-Jobs
DB-Nickname
Priority
X-Server-W
AMP-Access-Control-Allow-Source-Origin
X-TA-CDN-Provider
CF-IPCountry
X-Aspnetmvc-Version
X-Api-Version
Environment
X-PHP-Backend
Sid
Uber-Trace-Id
X-Proxy-Cache-Status
X-Fastly-Request-Id
X-Cache-Action
X-Cluster-Node
X-LSADC-Cache
User-Cache-Control
X-Response-Served-From
X-Original-Request-Id
X-Urbn-Site-Id
X-Uri
X-Fastcgi-Cache
X-Urbn-Context-Path
Locale
X-MP-GENERATED-AT
X-Mg-Request-UUID
X-DC
HostName
X-FB-TRIP-ID
X-TT-LOGID
DCR-Decision-By
X-Dispatcher-Server
Content-Secure-Policy
X-Ec-Fail
DCR-Processing-Time-Ms
X-Device-Os
X-D
X-Developer
Edge-Cache
X-Level-Front-Cache
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Hnp-Log
X-GeoIP-City
X-Gen-Mode
X-Generated-On
X-Forwarded-Site
X-Ig-Origin-Region
Candidate-Md5Url
X-Jungle-Id
Cache-Tv-Group
X-FC-Vary-Parameters
Fusion-Component-Id
Fusion-Template-Id
T-Server
X-Aed
Vix-Hermes-Req-Id
Surrogated-Key
Sslversion
X-BCube-Filmed-By
X-Bc-Bl
Server-Host
Wxu-Next-Commit
Wxu-Next-Hostname
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Dam
X-A-Ccd
Wxu-Next-Region
X-A
X-Bip
X-Bl-Debug
X-Conf
Magicmarker
MD5-Digest
Lang
Gannett-Cam-Experience-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
Meta-Geo-Continent
X-Clientip
X-Block-Status
Rendered-Blocks
Req-ID
Origin-Agent-Cluster
Origin
Ngx.Var.Host
X-Cache-NE
Fusion-Content-Id
A
X-UA-Device-Type
X-Platform
Cdn-Requestid
X-Origin-Expires
X-Nf-Request-Id
X-Node-Id
X-Op-Id-All
X-Org
X-Proto
X-Vtex-Remote-Cache
X-TIM-N
X-Thanos
X-SRCache-Key
X-Viewer-Country
X-ScT
X-Request-Start
X-Rojux
X-SB
X-ND-Cache
X-Tx-Id
X-Vdms-Version
X-NCache
X-Varnish-Hostname
X-Vdms-Path
X-Varnish-Beresp-Ttl
WP-Super-Cache
X-Tt-Logid
X-Core-Value
Host-ID
HA-Ipaddr
X-Content-Age
L5d-Success-Class
X-VTEX-Cache-Time
X-Mvc-Supplant-Cachable
X-RateLimit-Limit-Second
Ha-Gx-Prefs
X-Csrf-Jwt
X-Req
Fastly-SSL
X-Region-Sid
Fastly-Backend-Name
Ssr
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-CUA
X-Request-Time
X-RateLimit-Remaining-Second
X-VTEX-Cache-Server
X-Cache-Id
Server-Hostname
PFcat
Origin-EX
Powered-By
X-VarnishDD-TTL
X-Varnishpool
X-Test
Release
Server-Ext
Origin-CC
X-Via-Fastly
Sever-Int
X-Cdn-Srv
X-CGP
X-Scheme
X-SD-PageType
NM-Fastcgi-Cache
X-Loc
X-Backend-Instance
X-Cache-TTL-Remaining
Mail-Subject
DSUID
X-Gdpr
AKAMAI
XM
X-Client-Ip
X-Geo-Header
X-V-Cache
X-AK-Request-ID
X-Eu-Site
C-Via
X-Fastly-Cache
X-Amz-Storage-Class
X-GeoIP
X-HN
X-Nginx-Cache-Key
X-LiteSpeed-Cache-Control
W
We-Hiring
X-NMSegId
X-Service
X-Pubstack
X-Nyt-Route
Yak-Timeinfo
X-Gzip
X-Auth-Group-Type
X-App-Name
Content-Script-Type
Canary
X-Edge-Server
X-PAYTM-SRV-ID
X-WA-Info
Content-Style-Type
X-Powered-By-VTEX-Cache
X-Var-Ttl
X-HS-Content-Campaign-Id
X-Esi-Check
X-Auto-Login
CDCHOST
X-Origin-Time
Cdnsip
Cdn-Host
Cdn-Request-Time
Cdncip
X-Origin-Response-Time
X-VG-TLSProxy
X-Varnish-Authentication
X-VG-WebCache
X-BBC-Edge-Cache-Status
X-ApacheServer
X-Acquia-Purge-Cdn-Unconfigured
X-B3-Trace-ID
X-Varnish-Director
X-SVT-ORM-VERSION
X-Ad-Load-Variation
X-Render-Time
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-Varnish-Beresp-Status
X-Ig-Push-State
X-GeoIP-Country-Code
X-Wikidot-Static-Cache
X-From
X-Access
X-Policy
X-Location
X-Men
X-Micro-Cache
X-Mly-Id
Gh-Request-Id
X-Human
X-Mvc-Supplant-OutputCached
X-Fmm-Version
X-Wikidot-Backend
X-Cache-Bucket
X-Cache-Info
X-Section
X-Cache-Backend
X-Cache-Aspx
X-Sn-Servicetimems
X-Server-IP
X-CacheTTL
X-Contensis-Viewer-Groups
X-PERF
X-We-Are-Hiring
X-Fastly-Backend
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-Request-Host
X-Pool
X-SVT-ORM-RULES
X-Aicache-OS
Pramga
Apple-News-Services-Handled
Platform
Apple-News-Services-Host
Producers
Adler-Geo
X-Zone
Is-Eu
Redirect-Candidate
On-Server
Apple-News-Services-Parsed-Url
Cluster
Country-Code
Esi-Enabled
L
Click-Count-Error
Click-Count-Action-Start
Apple-News-Services-Request-Url
Cache-Key
Cache-Provider
RNT-Machine
Req-Svc-Chain
RNT-Time
Tube-Got-Eval
Tube-Return
V-Age
Web-Mar-Region
Tube-Get-Contents
Tube-Got-Results
X-ECache
True-Client-Country-4JS
X-ID
X-Ismobilevalue
X-Newrelic-Synthetics
Odigeo-Trace-Id
Machine
Fastly-GeoIP-CountryCode
NGX
X-Date
X-Tb-Optimization-Total-Bytes-Saved
X-Proxied-Request
X-Accel-Expires-Debug
X-Slack-Backend
X-Hash
X-Up
X-Slack-Shared-Secret-Outcome
X-Dc
X-AIR-PT
X-LB-ID
X-NodeID
X-Custom-Header
X-NGINX-Cache
Proxy-Firewall
X-Varnish-Hits
Fastly-Drupal-HTML
X-Cs
Datacenter
X-COUNTRY
Debug
X-Nananana
X-Pad
SID
Pics-Label
X-Via-Popv
X-DefHash
X-CACHE-GROUP
X-Via-Poph
X-HA-Backend
X-Refresh
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-DefElseHash
CloudFront-Viewer-Country
Locid
X-Varnish-CookieHashed-On
X-Via-Popn
X-Platform-Router
X-Amz-Meta-Cb-Modifiedtime
X-Servedbyhost
X-Depends
X-Akamai-Transformed
X-Platform-Cluster
X-Platform-Processor
X-Datadome
Mime-Version
X-LiteSpeed-Tag
X-CACHE-AGE
X-VC-TTL
GeoIP-Latitude
X-VHOST
X-TIME
X-LB-NoCache
X-M-Reqid
X-Cache-FS-Status
X-Old-Content-Length
X-M-Log
X-Parent-Response-Time
Ngx-Var-Key
X-Cached-By
X-B3-Parentspanid
X-CS
X-Moov-Xdn-Version
X-Moov-T
Server-ID
X-TH-Server
Cdn
X-DynaTrace-JS-Agent
Cross-Origin-Embedder-Policy-Report-Only
X-Nc
Resin-Trace
Server-Info
X-CDN-Cache-Status
X-Wa
Fastly-Drupal-Html
Cf-Ipcountry
BehaviorPad-Version
NtCoent-Length
X-Litespeed-Tag
GeoIp-Country-Code
X-ZONE
X-Presslabs-Stats
X-HITS
X-VCache
X-Application
X-Vgn-Hpd-Reason
X-S-Cookie
X-B-Cookie
X-User
X-External-Request-Id
X-Destination
X-Fpc
X-IAuth-Set-Uid
Cf-Device-Type
X-Srv
X-Vc
X-Zen-Fury
Uri
X-APP
FSS-Cache
X-NewRelic-App-Data
X-Providence-Cookie
X-Is-Crawler
X-TX-ID
X-Flags
X-Aspnet-Duration-Ms
X-Route-Name
X-Sigma
X-Instance-Name
X-Sigma-Backend
True-Client-IP
X-Cache-Date
X-Content-Length
True-Client-Ip
X-Rocket-Build-Number
X-Esi
CDN
X-HostName
Serverhost
X-DynaTrace
X-Varnish-Beresp-TTL
X-VServer
X-Dynatrace-Js-Agent
X-API-Version
Load-Balancing
X-Branch-Name
GeoIP-Country-Code
X-Segment-20210421
Tcn
S-Rt
X-Oracle-DMS-ECID
X-Page-View
X-HOST
Srv
Hostname
X-Cdn-Forward
X-Dispatcher-Number
Ohc-File-Size
Request-ID
Vc-Max-Age
X-B3-Spanid
X-RequestId
X-Dispatch
X-DataCenter
X-Cdn-Cache-Status
Product
X-NC
X-WA
X-FPC
Type
X-Sql-Count
X-Http-Reason
X-APP-VERSION
ServerName
X-Sql-Duration-Ms
Geoip-Latitude
X-Webkit-Csp-Report-Only
Server-Id
X-Irp-Debug
X-FL-QIT-DEBUG
Srvid
X-Correlation-ID
X-Ckpd-Fst-Backend
Cl-Cache
X-Bug-Bounty
X-Geo
X-Lb-Nocache
X-Via-SSL
X-SIPLIST1
IsBot
WZWS-RAY
X-Via-CDN
X-Via-Edge
Edge-Copy-Time
X-CSRF-TOKEN
CacheControlHeader
X-Owner
DataCenter
X-ServedByHost
X-VCL-Version
Cross-Origin-Opener-Policy-Report-Only
X-Core-Mission
X-App
X-Proxy-CacheRZ
MIME-Version
X-CACHE-KEY
XkeyRZ
Ohc-Cache-HIT
Origin-Trial
Cloudfront-Viewer-Country
Epwk-X-Cache
X-Hit
X-Cache-Ttl
X-Ua
X-Qloud-Router
N-Cache
CountryCode
X-Ha-Backend
X-Via-PopH
X-Via-PopV
X-Via-PopN
PICS-Label
X-Guploader-Uploadid
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Rtss
X-MiniProfiler-Ids
ServerHost
X-Lb-Id
X-MSEdge-Flight
X-MSEdge-Features
X-LAGOON
X-Amz-Meta-Opti
X-Fastly-Country-Code
Lb
X-Acquia-Purge-Tags
User-Agent
X-Acquia-Site
Warning
X-Akamai-Device-Characteristics
X-Service-Response-Time
X-Web-Server
Cneonction
X-Vmg-Version
X-Datacenter
Sm-Log-Id
X-Limited
X-Sqd-Ctime
X-Sqd-Stime
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Iplb-Request-Id
X-Litespeed-Cache-Control
X-Iplb-Instance
X-Amz-Meta-Sha256
X-Gamma-Serve
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Udemy-Cache-App-Namespace
X-Amz-Meta-S3b-Last-Modified
X-Dw-Trace-Id
X-Proxy-Cache-La3
Xkey-La3
Xkeylog
X-Cache-Type
X-Cdn-Request-ID
X-Forwarded-Path
Akamai-Cache-Status
X-Orig-Expires
X-Shop-Environment
X-Tenant
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Serial
X-Th-Server
X-Ramcache
X-Snapshot-Date
X-Check-Cacheable
X-RAMCache
Expect-Staple
X-Requestid
X-Akamai-Pragma-Client-IP
Ngx