Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
P3P
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Request-ID
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
Permissions-Policy
X-Turbo-Charged-By
X-Proxy-Cache
Xkey
X-Ws-Request-Id
X-Rq
X-Age
X-Vhost
X-Amz-Version-Id
X-Dispatcher
Cf-Apo-Via
X-Dns-Prefetch-Control
Allow
X-Swift-SaveTime
X-Swift-CacheTime
X-LiteSpeed-Cache
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-Host
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
X-Node
Content-Location
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
P3p
X-NWS-LOG-UUID
X-Country
Service-Worker-Allowed
X-Country-Code
X-CST
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
Rating
X-Litespeed-Cache
X-Rack-Cache
X-Url
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
X-Times
X-TtlSet
X-Vname
X-PC
Nginx-Cache
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Oneagent-Js-Injection
X-Server-Name
X-Edge
X-Mcache
X-Browser-Type
X-Midtier
X-Webkit-Csp
X-Powered-By-Plesk
X-ESI
X-Cnection
X-ECACHE
X-GitHub-Request-Id
Edge-Control
X-D2id
X-Upstream
X-Element-Page-Cache
Verso
X-MS-InvokeApp
X-Ac
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Exp-Id
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-FastCGI-Cache
X-B3-TraceId
X-Cache-TTL
Accept-Ch-Lifetime
X-Vcap-Request-Id
X-Ser
X-Abt-Application-Version
X-Navigation-Version
AR-CACHE
X-Dw-Request-Base-Id
SPRequestDuration
SPIisLatency
X-Mod-Pagespeed
SPRequestGuid
X-SharePointHealthScore
X-NF-Request-ID
Fastly-Restarts
X-Amz-Rid
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
Pagespeed
X-Middleton-Display
X-Sol
Display
X-Aws-Lambda-Call-Status
Edge-Cache-Tag
X-Mg-S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Client-IP
S
X-Ruxit-Js-Agent
X-Powered-CMS
X-Goog-Hash
X-Middleton-Response
Response
X-Version
Cache-Status
Access-Control-Request-Method
X-VARITI-CCR
X-Amzn-Trace-Id
X-Fastly-Request-ID
X-ARC
X-Cache-Key
RTSS
X-Ratelimit-Limit
X-Content-Digest
X-TraceId
Cross-Origin-Resource-Policy
X-Forwarded-For
X-T
X-Recruiting
Realpath
X-Varnish-TTL
X-PDP-UNCACHING-HASH
X-RateLimit-Remaining
X-Ratelimit-Remaining
X-Correlation-Id
X-TTL
Front-End-Https
X-MSEdge-Ref
Fastcgi-Cache
X-Cached
MS-Author-Via
Content-MD5
X-Ua-Browser
X-HS-Hub-Id
X-HS-Content-Id
X-Shield-Request-Id
X-HS-Cache-Config
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
MicrosoftSharePointTeamServices
X-Request-Received
X-Protected-By
X-Request-Processing-Time
Server-Node
Payment
Public-Key-Pins
X-LLID
TP-Cache
X-HS-Combine-CSS
X-Frontend
X-Forwarded-Proto
X-Pinterest-Rid
Pinterest-Generated-By
Arr-Disable-Session-Affinity
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Pinterest-Version
X-FTR-Expires
X-Distributor
X-HP-Trace-Id
X-Jurisdiction
X-Accel-Expires
X-HP-Webp
X-ORACLE-DMS-RID
Count-Hit
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-GUploader-UploadID
X-Origin-Server
X-Server-ID
X-LB-Cache
X-NODE
X-Ezoic-Cdn
X-Microsite
X-Request-Handler-Origin-Region
X-Ttl
X-PressLabs-Stats
X-Content-Security-Policy-Report-Only
X-Activity-Id
X-AppVersion
X-Az
Host
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Mrf-Cache-Status
X-Cluster-Name
MRF-Tech
X-Varnish-Server
X-Www-Served-By
X-B3-TraceId-Primal
X-Varnish-Backend
Cache-Tags
X-App-Server
Accept-Charset
Retry-After
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-Ua-Device
X-Newrelic-App-Data
Cleartype
X-Hostname
X-CSRF-Token
X-Goog-Metageneration
X-Envoy-Decorator-Operation
X-Geo-Country
X-ORACLE-DMS-ECID
X-Hits
X-Origin-Cache-Key
X-NGENIX-Cache
Referer-Policy
X-Git-Hash
X-Upgrade-Enabled
TP-L2-Cache
Filterid
X-Unique-Id
X-DIS-Request-ID
X-Azure-Ref
Access-Control-Allow-Method
X-Seen-By
TCN
X-Tt-Trace-Host
X-Hcs-Proxy-Type
X-Load-Cache
X-CCDN-Origin-Time
X-Tt-Trace-Tag
X-CCDN-CacheTTL
X-Proxy
X-F-Cache
X-Revision
X-Trace-Id
X-Request-Guid
X-Grace
Section-Io-Cache
Healthy
X-B3-Sampled
X-Logged-In
DC
X-B
X-Cache-Control
X-Type
X-TT
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Contextid
Paypal-Debug-Id
X-Debug
X-Fb-Rlafr
X-FB-Debug
X-Debug-Info
X-Page-Id
X-Id
X-N
X-Px
X-Mobile
Viewport
X-Oracle-Dms-Ecid
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Goog-Stored-Content-Encoding
Fastly-SIE
Fastly-SWR
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Whom
X-XRDS-LOCATION
X-Varnish-Ttl
X-Oracle-Dms-Rid
Content-Disposition
Charset
X-Content-Options
X-Via-JSL
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
Version
X-Time
X-Template
X-Varnish-Grace
X-Webkit-CSP
X-Origin-Cache
X-Cache-Grace
X-Magnolia-Registration
X-Wix-Request-Id
Surrogate-Key
X-Rid
X-RateLimit-Limit
X-B3-SpanId
X-App-Environment
X-Signature
X-B-Cache
SRV
X-RemovedCookies
X-ProcessESI
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Debug-IsConnected
X-Debug-IsPreview
X-Rule
X-Node-Name
X-EdgeConnect-Cache-Status
X-G
SD-X-WS
X-Amz-Replication-Status
X-Datadog-Sampled
Ms-Operation-Id
X-Hl-Ver
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-RTag
X-UUID
MS-CV
X-Backend-Name
X-Adobe-Content
X-Adobe-Loc
X-FW-Server
X-FW-Version
X-Instance
X-Storage
X-FW-Type
X-FW-Static
X-FW-Hash
X-FW-Serve
X-Language
X-FW-Dynamic
ServerID
X-Device-Type
NGB
X-Is-Bot
X-NYM-Debug-Backend
X-Rendered-As
GEO-INFO
X-Cacheable-TTL
X-L-Path
X-IPS-LoggedIn
X-Proxy-Cache-Info
X-Region
X-Status
X-User-Agent
X-Environment-Context
X-Cache-Hit
X-Amzn-Remapped-Content-Length
Country
Countrycode
Liferay-Portal
X-NWS-UUID-VERIFY
X-Source
X-Real-IP
X-ServerID
X-URL
Cross-Origin-Window-Policy
Akamai-GRN
X-WP-CF-Super-Cache-Active
X-Sucuri-ID
X-RateLimit-Reset
X-Sucuri-Cache
Amp-Access-Control-Allow-Source-Origin
X-Cache-Age
OT-Force-Account-Verify
X-Servername
X-UA
X-RM-Cache-TTL
X-VC-Cache
From-Origin
X-WebKit-CSP-Report-Only
Front
X-Framework
X-Air-Pt
Upgrade-Insecure-Requests
X-Wormhole-Sdk
Backend
X-INCAP-ABP
X-Mode
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-AB
X-Content-Powered-By
X-Akamai-Request-ID2
X-Cache-Time
Xet-Cookie
Refresh
X-Xrds-Location
X-Handled-By
X-Nginx-Cache
X-DataDome
X-Edge-Location
X-Endurance-Cache-Level
Accept-Language
X-HTML-Minification-Powered-By
X-Rn-Rsrv
Frame-Options
Filters
X-Rewrite-Enabled
X-SaId
X-RCS-CacheZone
X-Origin-TTL
X-JoinUs
Url
X-UPSTREAM-Address
Meta-Geo
X-Xfnlog-Site
X-SRV
X-Origin-CC
X-LJ-Flow-ID
TWC-Connection-Speed
ServedBy
X-Origin-Date
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-GeoIP-Country
X-PHP-Host
X-No-Session
X-Container-Uri
X-AWS-Id
Cache
X-Git-Commit
X-Origin-Hint
X-Cluster
X-Provided-By
Webcakes-App-Name
X-Tumblr-Pixel-2
Webcakes-Region
X-VWS-Id
Webcakes-App-Version
X-Akamai-Edgescape
X-CDN-Forward
X-Vcache
X-Cache-Operation
X-Cache-Rule
Property-Id
X-Reqid
TWC-Privacy
X-Labrador-Cache-Channel
X-Webstats-RespID
X-Cache-Debug
X-Web-Node
WPO-Cache-Status
X-R9-Blue-Green-Version
X-Zipkin-Id
X-Served-From
X-Scope-Id
X-Routing-Service
X-Cms-Context
X-Redis-Cache
X-Accel-Version
Cache-Hits
X-Varnish-Cache-Hits
X-IPLB-Instance
X-IPLB-Request-ID
X-Restarts
X-Adobe-Source
X-Hosted-By
WPO-Cache-Message
X-Fetched-On
X-Logging-Id
Web-Mar-Node
Section-Io-Id
X-Cloudmap
Mn-Server-Ip
X-Proxied
X-Extlb
Atl-Traceid
X-XRDS-Location
X-Ratelimit-Reset
Webserver
X-Forwarded-Host
X-Format
X-Frame-Option
X-Upstream-Ht
X-Varnish-Age
X-Upstream-Ct
X-Director
Selected-Fe
X-Site-Version
X-Locale
X-BYPASS-REASON
X-Lambda-Id
X-Drupal-Cache-Tags
X-Tncms
X-Soup
X-ProxyCache-Status
X-Say-Cacheable
X-Say-TTL
X-Skip-Cache
X-SayCDN-TTL
X-ProxyCache-Key
X-Proxy-Build
X-Ms-Request-Id
X-Loop
X-Ms-Version
X-Timing-Wait
X-Tb
Access-Control-Request-Headers
X-VCT
Apigw-Requestid
X-Azure-Ref-OriginShield
X-CMSURLCustom
X-Varnish-Beresp-Grace
X-Detected-As
X-GeoCode
X-Geo-Region
X-Generation-Time
X-Cache-Host
X-Sorting-Hat-PodId
Thinkindot-Control
Thinkindot-CacheControl-Type
Xserver
X-Alternate-Cache-Key
X-GeoCountry
X-Browser-Name
X-Is-Desktop
X-Sorting-Hat-ShopId
X-S
X-ShardId
X-Shield-Cache-Expires
X-Shopify-Stage
X-ShopId
X-Storefront-Renderer-Rendered
X-Tcp-Rtt
X-Is-Mobile
Thinkindot-CacheControl
X-Is-Supported-Browser
X-Is-Tablet
X-Thinkindot-L3
X-Origin
X-Httpd
X-Drupal-Cache-Contexts
TDXMobile
X-Generated-By
X-Cache-Status-Check
LB
X-Cdn-Origin
X-VC
X-Buckets
X-Lagoon
X-RID
X-Optimistic-Header
X-Rocket-Nginx-Serving-Static
X-Request-URI
Fastcgi-Useragent
Source
X-Worker
X-Vercel-Id
X-WP-CF-Super-Cache-Cookies-Bypass
X-Vercel-Cache
Azure-RegionName
Azure-InstanceId
X-ID
Azure-SiteName
Azure-Version
Azure-SlotName
Protected
Node
Onion-Location
Expiry
X-Pass-Why
X-Vcl-Version
X-Connection-Hash
CDN-Cache
CDN-RequestPullSuccess
CDN-CachedAt
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestPullCode
CDN-Uid
X-TA-CDN-Provider
Cross-Origin-Embedder-Policy
X-Api-Version
X-GEO
X-App-Version
X-Cache-Expired-At
X-Tumblr-Pixel-3
X-Tec-Api-Version
X-Tec-Api-Root
X-Client-Ip
X-Tec-Api-Origin
X-Ismobilevalue
Alternate-Protocol
X-Cache-Server
X-PHP-Backend
Environment
X-Server-W
AMP-Access-Control-Allow-Source-Origin
DB-Nickname
Uber-Trace-Id
X-Tt-Logid
X-Proxy-Cache-Status
Cdn-Requestid
Priority
X-Jobs
CF-IPCountry
X-Cache-Action
X-DC
X-Fastly-Request-Id
X-Urbn-Site-Id
X-Cluster-Node
Locale
CDN-RequestId
X-Urbn-Context-Path
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Mg-Request-UUID
User-Cache-Control
X-Fastcgi-Cache
Sid
X-Tx-Id
X-LSADC-Cache
X-B3-Traceid
Cache-Tv-Group
HostName
X-MP-GENERATED-AT
Fusion-Source
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Lang
Magicmarker
DCR-Processing-Time-Ms
A
Candidate-Md5Url
Content-Secure-Policy
MD5-Digest
X-Auth-Group-Type
Edge-Cache
Gannett-Cam-Experience-Id
Ngx.Var.Host
Meta-Geo-Continent
DCR-Decision-By
X-A-Wwc
X-Jungle-Id
X-Ig-Push-State
X-Level-Front-Cache
X-NCache
X-Op-Id-All
X-ND-Cache
X-Ig-Origin-Region
X-Hnp-Log
X-FB-TRIP-ID
X-Esi-Check
X-Gen-Mode
X-Generated-On
X-Gzip
X-GeoIP-City
X-Org
X-Origin-Expires
X-Vdms-Version
X-Varnish-Hostname
X-Viewer-Country
X-VTEX-Cache-Server
X-Vtex-Remote-Cache
X-VTEX-Cache-Time
X-UA-Device-Type
X-TIM-N
X-Rojux
X-Powered-By-VTEX-Cache
X-SB
X-ScT
X-SRCache-Key
X-Epic-Correlation-Id
X-Ec-GeoHdr
Wxu-Next-Region
Wxu-Next-Hostname
X-A
X-A-Ccd
X-A-Dcw
X-A-Dam
Wxu-Next-Commit
Vix-Hermes-Req-Id
Server-Host
Origin-Agent-Cluster
Sslversion
Surrogated-Key
T-Server
X-A-Dgt
X-Aed
X-D
X-Content-Age
X-Developer
X-Device-Os
X-Ec-Fail
X-Dispatcher-Server
X-Conf
X-Cache-NE
X-BCube-Filmed-By
X-Bc-Bl
X-Bl-Debug
X-Block-Status
X-Cache-Id
Origin
Rendered-Blocks
X-Varnish-Beresp-Ttl
X-Origin-Response-Time
X-Nf-Request-Id
X-Debug-Cache-Fetch
X-Core-Value
X-Cdn-Srv
X-Cache-Info
X-Cache-TTL-Remaining
X-Debug-Cache-Store
X-Clientip
X-Fastly-Cache
X-Gdpr
X-GeoIP
X-Forwarded-Site
X-Fmm-Version
X-Cache-Bucket
X-FC-Vary-Parameters
X-Edge-Server
X-Backend-Instance
Powered-By
Req-ID
Server-Ext
PFcat
Origin-EX
NM-Fastcgi-Cache
Origin-CC
Server-Hostname
Sever-Int
X-Auto-Login
X-GeoIP-Country-Code
X-App-Name
X-Amz-Storage-Class
Ssr
X-AK-Request-ID
X-Bip
X-GeoIP-Region-Code
X-Tb-Optimization-Total-Bytes-Saved
X-Test
X-Thanos
X-SD-PageType
X-Scheme
X-Request-Start
X-Request-Time
X-V-Cache
X-Varnish-Director
XM
Odigeo-Trace-Id
X-Via-Fastly
X-VG-WebCache
X-VarnishDD-TTL
X-Vdms-Path
X-Req
X-RateLimit-Remaining-Second
X-Nginx-Cache-Key
X-NMSegId
X-Node-Id
X-Mvc-Supplant-Cachable
X-Loc
X-HN
X-HS-Content-Campaign-Id
X-Nyt-Route
X-Origin-Time
X-Pubstack
X-RateLimit-Limit-Second
X-Proto
X-Policy
X-PAYTM-SRV-ID
X-Platform
Host-ID
X-Geo-Header
X-Service
Content-Style-Type
Cdn-Host
Content-Script-Type
Cdncip
Cdn-Request-Time
AKAMAI
CDCHOST
Fastly-Backend-Name
Cdnsip
C-Via
Cache-Provider
Fastly-SSL
X-Fastly-Backend
X-Eu-Site
X-From
Cache-Key
X-GoCache-CacheStatus
Canary
X-Ec-Custom-Error
X-Csrf-Jwt
Country-Code
X-BBC-Edge-Cache-Status
X-Newrelic-Synthetics
X-B3-Trace-ID
DSUID
X-Ad-Load-Variation
X-Aicache-OS
X-Cache-Aspx
X-Cache-Backend
Click-Count-Action-Start
X-CUA
X-Contensis-Viewer-Groups
Click-Count-Error
Cluster
X-CGP
X-DPWN-IS-SECURE
Apple-News-Services-Request-Url
X-Varnish-Authentication
X-Varnish-Beresp-Status
X-Varnishpool
X-Var-Ttl
X-SVT-ORM-VERSION
X-Response-Served-From
X-SVT-ORM-RULES
X-VG-TLSProxy
X-WA-Info
X-Region-Sid
X-Custom-Header
Yak-Timeinfo
X-Wikidot-Static-Cache
X-We-Are-Hiring
X-Wikidot-Backend
X-Sn-Servicetimems
X-Section
X-Mly-Id
Apple-News-Services-Parsed-Url
X-Mvc-Supplant-OutputCached
X-Micro-Cache
X-Men
X-Acquia-Purge-Cdn-Unconfigured
X-Location
Is-Eu
Apple-News-Services-Handled
X-Original-Request-Id
X-Proxied-Request
X-Pool
X-Zone
X-NodeID
Adler-Geo
X-Human
Apple-News-Services-Host
Esi-Enabled
True-Client-Country-4JS
RNT-Time
RNT-Machine
Fastly-GeoIP-CountryCode
Req-Svc-Chain
Tube-Get-Contents
Tube-Got-Eval
W
We-Hiring
V-Age
Tube-Return
Tube-Got-Results
Release
Redirect-Candidate
X-ECache
Mail-Subject
Machine
X-Uri
L
L5d-Success-Class
HA-Ipaddr
X-Access
Pramga
Producers
Platform
Gh-Request-Id
Ha-Gx-Prefs
Web-Mar-Region
On-Server
X-HITS
X-LiteSpeed-Cache-Control
X-Hash
NGX
X-Accel-Expires-Debug
X-Date
X-Slack-Backend
X-Server-IP
X-Up
X-Slack-Shared-Secret-Outcome
X-CacheTTL
X-Request-Host
Proxy-Firewall
WP-Super-Cache
X-TT-LOGID
X-AIR-PT
SID
X-NGINX-Cache
X-ApacheServer
X-DefElseHash
X-Varnish-CookieINHashed-On
Debug
X-CACHE-AGE
X-PERF
X-DefHash
X-Varnish-Remaining-TTL
X-Varnish-Hits
X-Varnish-CookieHashed-On
X-Render-Time
X-Pad
Mime-Version
Fastly-Drupal-HTML
X-COUNTRY
X-Dc
X-Depends
X-LB-ID
X-Nananana
X-Refresh
CloudFront-Viewer-Country
X-CACHE-GROUP
X-Via-Popn
X-Cs
X-HA-Backend
X-Via-Popv
X-Via-Poph
Pics-Label
X-Cache-FS-Status
X-Akamai-Transformed
X-Parent-Response-Time
X-Servedbyhost
Datacenter
Locid
GeoIP-Latitude
X-VHOST
X-TIME
X-M-Reqid
X-Amz-Meta-Cb-Modifiedtime
X-LB-NoCache
X-Datadome
X-M-Log
X-VC-TTL
X-B3-Parentspanid
X-Platform-Router
X-Platform-Cluster
Server-Info
X-Cached-By
X-Platform-Processor
X-CS
BehaviorPad-Version
Server-ID
X-Old-Content-Length
Ngx-Var-Key
X-Litespeed-Tag
X-Nc
X-CDN-Cache-Status
X-APP
X-Wa
Cdn
X-LiteSpeed-Tag
Resin-Trace
Fastly-Drupal-Html
X-DynaTrace-JS-Agent
Cf-Ipcountry
X-Vc
X-TH-Server
GeoIp-Country-Code
X-Presslabs-Stats
X-Moov-Xdn-Version
X-Moov-T
Cross-Origin-Embedder-Policy-Report-Only
X-VCache
NtCoent-Length
X-Fpc
X-Content-Length
X-Vgn-Hpd-Reason
X-IAuth-Set-Uid
Uri
X-ZONE
X-NewRelic-App-Data
FSS-Cache
True-Client-Ip
X-External-Request-Id
X-Esi
X-User
X-S-Cookie
Serverhost
True-Client-IP
X-Destination
X-B-Cookie
Cf-Device-Type
X-Application
X-TX-ID
X-Dynatrace-Js-Agent
X-HostName
X-SERVER-NAME
CDN
X-Srv
X-Dispatcher-Number
X-Varnish-Beresp-TTL
X-Zen-Fury
Vc-Max-Age
X-Instance-Name
X-Cache-Date
GeoIP-Country-Code
X-RequestId
Tcn
S-Rt
X-Sigma-Backend
X-Rocket-Build-Number
X-Sigma
X-Oracle-DMS-ECID
X-HOST
X-API-Version
X-VServer
X-Cdn-Cache-Status
Srv
Product
Load-Balancing
Request-ID
X-Branch-Name
Hostname
X-DynaTrace
X-FPC
X-WA
X-NC
X-Dispatch
X-Segment-20210421
X-Route-Name
X-Is-Crawler
X-Flags
X-Cdn-Forward
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-CACHE-KEY
X-Ckpd-Fst-Backend
X-B3-Spanid
X-APP-VERSION
Ohc-File-Size
X-Bug-Bounty
Server-Id
Srvid
X-DataCenter
Geoip-Latitude
X-FL-QIT-DEBUG
X-Webkit-Csp-Report-Only
ServerName
X-Page-View
Type
CacheControlHeader
X-Lb-Nocache
X-Geo
X-Irp-Debug
Origin-Trial
X-ServedByHost
DataCenter
X-Nf-Ats-Version
X-Nf-Country
X-HubSpot-Correlation-Id
X-Sql-Duration-Ms
X-VCL-Version
X-Http-Reason
X-Nf-Language
X-Sql-Count
Cl-Cache
Cloudfront-Viewer-Country
Epwk-X-Cache
X-Cache-Ttl
User-Agent
Cneonction
X-Correlation-ID
X-Vmg-Version
X-App
X-Akamai-Device-Characteristics
Cross-Origin-Opener-Policy-Report-Only
X-Via-CDN
X-Via-Edge
X-Via-SSL
Ohc-Cache-HIT
X-SIPLIST1
X-Owner
X-Ua
IsBot
Edge-Copy-Time
X-Ha-Backend
X-Via-PopV
PICS-Label
X-Via-PopH
X-Via-PopN
X-Srcache-Store-Status
Rtss
X-Srcache-Fetch-Status
WZWS-RAY
X-Proxy-CacheRZ
XkeyRZ
MIME-Version
Cmsid
ServerHost
X-MiniProfiler-Ids
X-Core-Mission
Cmstype
X-Info
X-Lb-Id
Lb
X-Datacenter
X-Acquia-Application-Trace
X-MSEdge-Features
X-Service-Response-Time
X-Sqd-Stime
X-Gamma-Serve
Xc-Version
X-Limited
X-Sqd-Ctime
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
Sm-Log-Id
N-Cache
X-Qloud-Router
X-Fastly-Country-Code
X-Web-Server
X-MSEdge-Flight
Warning
X-LAGOON
X-Litespeed-Cache-Control
CountryCode
Servername
X-Hit
X-Akamai-Pragma-Client-IP
X-Amz-Meta-Opti
X-Serial
X-RAMCache
X-Check-Cacheable
X-IN-APIGATEWAY
Ngx
X-Udemy-Cache-App-Namespace
X-Amz-Meta-Sha256
X-Amz-Meta-S3b-Last-Modified
X-Requestid
X-Snapshot-Date
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-Ramcache
X-Th-Server