Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Ua-Compatible
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
Permissions-Policy
X-Rq
X-Age
X-Vhost
X-Amz-Version-Id
X-Dns-Prefetch-Control
Allow
X-Dispatcher
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-LiteSpeed-Cache
P3p
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-WebKit-CSP
X-Host
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Litespeed-Cache
Content-Location
X-Application-Context
X-Ruxit-JS-Agent
X-Node
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-NWS-LOG-UUID
X-CST
Service-Worker-Allowed
X-Country-Code
X-Country
X-Content-Type
X-Url
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Oneagent-Js-Injection
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Server-Name
X-FTR-Request-ID
X-Times
X-PC
X-Vname
X-TtlSet
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Webkit-Csp
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-ESI
X-Cnection
X-Upstream
X-ECACHE
X-GitHub-Request-Id
X-MS-InvokeApp
Edge-Control
X-D2id
Verso
X-Element-Page-Cache
X-Ac
AR-SID
AR-Request-ID
AR-PoweredBy
X-Kinja
X-Cdn-Fetch
AR-ATIME
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Ser
X-Vcap-Request-Id
X-Cache-TTL
X-Navigation-Version
X-Abt-Application-Version
X-B3-TraceId
X-Aws-Lambda-Call-Status
SPIisLatency
SPRequestDuration
X-Mod-Pagespeed
AR-CACHE
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
Fastly-Restarts
X-Client-IP
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Sol
X-Middleton-Display
Pagespeed
Display
Edge-Cache-Tag
X-Mg-S
X-Kinsta-Cache
X-Edge-Location-Klb
S
X-Powered-CMS
Response
X-Middleton-Response
X-Amzn-Trace-Id
Cache-Status
X-Cache-Key
Access-Control-Request-Method
X-Version
X-VARITI-CCR
X-Goog-Hash
X-Fastly-Request-ID
X-ARC
X-RateLimit-Remaining
RTSS
X-Content-Digest
X-TraceId
X-Forwarded-For
Cross-Origin-Resource-Policy
X-Recruiting
X-T
Realpath
X-Ratelimit-Limit
X-Correlation-Id
X-Varnish-TTL
X-MSEdge-Ref
Front-End-Https
Fastcgi-Cache
X-Pinterest-Rid
MS-Author-Via
Pinterest-Version
Pinterest-Generated-By
X-Cached
X-PDP-UNCACHING-HASH
Content-MD5
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Ua-Browser
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
Server-Node
Payment
X-FTR-Balancer
X-Protected-By
X-Shield-Request-Id
X-Request-Processing-Time
X-Request-Received
MicrosoftSharePointTeamServices
Public-Key-Pins
X-HS-Combine-CSS
X-Forwarded-Proto
TP-Cache
Arr-Disable-Session-Affinity
X-LLID
X-TTL
X-Ratelimit-Remaining
X-Frontend
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ttl
X-Distributor
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-FTR-Expires
X-Server-ID
X-Accel-Expires
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-NODE
Count-Hit
X-ORACLE-DMS-RID
X-GUploader-UploadID
X-Origin-Server
X-LB-Cache
X-Origin-Cache-Key
X-Ezoic-Cdn
X-Content-Security-Policy-Report-Only
X-Microsite
X-Request-Handler-Origin-Region
X-AppVersion
X-Az
X-Activity-Id
Host
X-Www-Served-By
X-B3-TraceId-Primal
MRF-Tech
X-Ua-Device
Mrf-Cache-Status
X-Varnish-Backend
X-Cluster-Name
X-App-Server
Cache-Tags
X-Hits
X-Varnish-Server
Retry-After
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-PressLabs-Stats
X-Hostname
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Geo-Country
Cleartype
X-NGENIX-Cache
Referer-Policy
X-Id
X-Envoy-Decorator-Operation
X-Goog-Metageneration
X-DIS-Request-ID
X-CSRF-Token
X-Upgrade-Enabled
X-Newrelic-App-Data
TP-L2-Cache
X-Seen-By
X-Git-Hash
Access-Control-Allow-Method
X-Azure-Ref
X-Oracle-Dms-Ecid
TCN
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Load-Cache
X-Unique-Id
X-Tt-Trace-Tag
X-F-Cache
X-Tt-Trace-Host
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Proxy
Filterid
X-ORACLE-DMS-ECID
X-Grace
Healthy
X-Revision
X-Trace-Id
X-Px
X-Cache-Control
Section-Io-Cache
X-Request-Guid
X-Debug-Info
Paypal-Debug-Id
X-Contextid
DC
X-B
X-Page-Id
X-TT
X-Type
X-Logged-In
X-B3-Sampled
X-FB-Debug
X-Fb-Rlafr
X-N
X-Mobile
X-RateLimit-Limit
X-Debug
Viewport
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-XRDS-LOCATION
X-Varnish-Ttl
X-Oracle-Dms-Rid
X-Whom
Fastly-SWR
X-Template
Fastly-SIE
X-Time
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Charset
X-Datadog-Parent-Id
X-Webkit-CSP
X-Language
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Cache-Grace
X-Content-Options
X-Via-JSL
X-Magnolia-Registration
Content-Disposition
Version
X-Wix-Request-Id
X-Varnish-Grace
X-EdgeConnect-Cache-Status
X-App-Environment
X-B-Cache
X-Signature
X-Origin-Cache
X-ProcessESI
SRV
X-RemovedCookies
X-Rule
VIX-Pulpo-Upstream-Status
X-Node-Name
VIX-Pulpo-Node
X-RateLimit-Reset
X-Tumblr-Pixel-0
X-B3-SpanId
X-Yottaa-Optimizations
X-Tumblr-User
X-Tumblr-Pixel
X-Hl-Ver
X-Debug-IsConnected
X-Yottaa-Metrics
X-Tumblr-Pixel-1
X-Backend-Name
X-Debug-IsPreview
MS-CV
SD-X-WS
X-RTag
X-Amzn-Remapped-Content-Length
X-UUID
X-G
X-Amz-Replication-Status
X-Datadog-Sampled
Ms-Operation-Id
X-Proxy-Cache-Info
X-FW-Dynamic
ServerID
X-FW-Hash
GEO-INFO
X-Instance
X-FW-Version
X-Adobe-Content
X-Device-Type
X-Adobe-Loc
X-Storage
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Server
Countrycode
Liferay-Portal
X-Is-Bot
X-NYM-Debug-Backend
NGB
X-Rendered-As
X-User-Agent
X-IPS-LoggedIn
X-Cacheable-TTL
Country
X-L-Path
X-Region
X-Cache-Hit
X-Status
X-Environment-Context
X-Real-IP
Surrogate-Key
X-Rid
X-ServerID
X-NWS-UUID-VERIFY
X-Source
X-Cache-Age
Akamai-GRN
X-Sucuri-ID
X-Sucuri-Cache
X-WP-CF-Super-Cache-Active
OT-Force-Account-Verify
X-Servername
Amp-Access-Control-Allow-Source-Origin
Cross-Origin-Window-Policy
X-UA
X-VC-Cache
X-WebKit-CSP-Report-Only
From-Origin
X-RM-Cache-TTL
Upgrade-Insecure-Requests
X-Framework
Backend
Front
X-INCAP-ABP
X-Air-Pt
X-Mode
X-Xrds-Location
Refresh
X-AB
X-Wormhole-Sdk
X-Air-Hostname
X-Content-Powered-By
X-Air-Source
X-Air-Trace-Id
X-Cache-Time
X-Handled-By
X-Akamai-Request-ID2
X-RID
X-HTML-Minification-Powered-By
Frame-Options
Xet-Cookie
X-DataDome
X-Edge-Location
X-Endurance-Cache-Level
X-Buckets
X-JoinUs
ServedBy
X-CDN-Forward
Meta-Geo
Filters
X-Cluster
Selected-Fe
X-Reqid
X-Rewrite-Enabled
X-Origin-CC
X-Origin-TTL
X-RCS-CacheZone
X-Rn-Rsrv
X-SaId
X-UPSTREAM-Address
X-Webstats-RespID
X-Xfnlog-Site
X-Proxy-Build
X-Timing-Wait
Url
X-Origin-Date
X-No-Session
Webserver
X-VCT
X-VWS-Id
X-Git-Commit
X-IPLB-Instance
X-Tumblr-Pixel-2
X-Provided-By
X-Azure-Ref-OriginShield
X-IPLB-Request-ID
WPO-Cache-Message
WPO-Cache-Status
X-Cache-Rule
X-Cache-Operation
Atl-Traceid
Cache-Hits
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
X-Akamai-Edgescape
Webcakes-Region
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Container-Uri
X-Drupal-Cache-Tags
Property-Id
X-AWS-Id
TWC-Device-Class
TWC-Connection-Speed
X-Labrador-Cache-Channel
Cache
X-Origin-Hint
X-R9-Blue-Green-Version
X-SRV
X-LJ-Flow-ID
X-Served-From
X-Origin
X-Logging-Id
X-PHP-Host
X-BYPASS-REASON
X-Web-Node
X-Restarts
Mn-Server-Ip
X-Httpd
X-Varnish-Cache-Hits
X-Ms-Version
X-Generation-Time
X-Cms-Context
X-Drupal-Cache-Contexts
X-Fetched-On
X-Vcache
X-Cache-Status-Check
X-Redis-Cache
Accept-Language
X-CMSURLCustom
X-Cache-Debug
X-Scope-Id
Access-Control-Request-Headers
X-Tb
Thinkindot-Control
X-ProxyCache-Status
Web-Mar-Node
X-Site-Version
X-Accel-Version
X-ProxyCache-Key
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Ms-Request-Id
X-Thinkindot-L3
Section-Io-Id
X-Shield-Cache-Expires
X-Adobe-Source
TDXMobile
X-Locale
X-Browser-Name
X-Proxied
X-Format
X-Extlb
X-Frame-Option
X-Director
X-Upstream-Ct
X-Cloudmap
X-Upstream-Ht
Apigw-Requestid
X-Zipkin-Id
X-Tcp-Rtt
X-SayCDN-TTL
X-Say-TTL
X-Soup
X-Is-Desktop
X-Is-Tablet
X-VC
X-Is-Supported-Browser
X-Is-Mobile
X-S
X-Say-Cacheable
X-Geo-Region
X-Routing-Service
X-Hosted-By
X-Nginx-Cache
X-Tncms
X-Detected-As
X-Lambda-Id
X-GeoCode
X-Forwarded-Host
X-Cache-Host
X-Skip-Cache
X-Varnish-Beresp-Grace
X-Loop
X-Varnish-Age
X-GeoCountry
Xserver
X-Storefront-Renderer-Rendered
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Generated-By
X-ShardId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Cdn-Origin
X-Optimistic-Header
X-Worker
X-Lagoon
X-Rocket-Nginx-Serving-Static
X-XRDS-Location
X-Vercel-Cache
X-Vercel-Id
Source
Azure-InstanceId
Azure-SiteName
X-Tec-Api-Origin
Azure-SlotName
Azure-Version
X-Tec-Api-Version
X-Tec-Api-Root
X-B3-Traceid
Azure-RegionName
LB
X-Request-URI
Node
X-TA-CDN-Provider
X-Ratelimit-Reset
X-WP-CF-Super-Cache-Cookies-Bypass
CDN-Cache
CDN-CachedAt
X-Pass-Why
CDN-RequestCountryCode
CDN-Uid
CDN-EdgeStorageId
Fastcgi-Useragent
CDN-RequestPullSuccess
Protected
CDN-PullZone
CDN-RequestPullCode
X-URL
Cross-Origin-Embedder-Policy
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Vcl-Version
X-Connection-Hash
X-App-Version
Expiry
X-GEO
X-Tumblr-Pixel-3
CDN-RequestId
Onion-Location
Alternate-Protocol
X-Cache-Expired-At
AMP-Access-Control-Allow-Source-Origin
X-Cache-Server
X-PHP-Backend
X-Api-Version
DB-Nickname
X-Jobs
X-Server-W
X-COUNTRY
Priority
X-Fastly-Request-Id
Environment
CF-IPCountry
Uber-Trace-Id
X-Proxy-Cache-Status
X-Fastcgi-Cache
Sid
X-Cluster-Node
X-Cache-Action
X-Urbn-Site-Id
User-Cache-Control
Locale
X-Urbn-Context-Path
X-LSADC-Cache
X-Uri
X-Mg-Request-UUID
X-DC
X-Original-Request-Id
X-Response-Served-From
X-Tx-Id
HostName
Cdn-Requestid
X-Tt-Logid
X-MP-GENERATED-AT
X-Conf
X-VTEX-Cache-Time
X-Hnp-Log
X-Viewer-Country
X-Content-Age
X-Gzip
Ngx.Var.Host
X-Vdms-Version
X-Clientip
X-NCache
X-Cache-NE
X-Dispatcher-Server
X-Node-Id
X-Cache-Id
X-Mvc-Supplant-Cachable
X-Level-Front-Cache
Origin
X-VTEX-Cache-Server
X-Ig-Origin-Region
X-Jungle-Id
Origin-Agent-Cluster
X-Vtex-Remote-Cache
MD5-Digest
Fusion-Deployment-Id
Content-Secure-Policy
Fusion-Source
X-Epic-Correlation-Id
Fusion-Template-Id
X-Esi-Check
Fusion-Content-Source
X-Ec-GeoHdr
Edge-Cache
Fusion-Component-Id
Fusion-Content-Id
X-Ec-Fail
DCR-Decision-By
DCR-Processing-Time-Ms
Gannett-Cam-Experience-Id
X-FB-TRIP-ID
A
X-Gen-Mode
X-Generated-On
Magicmarker
X-Op-Id-All
X-GeoIP-City
Lang
X-Forwarded-Site
X-Developer
X-Device-Os
Candidate-Md5Url
Cache-Tv-Group
X-D
X-FC-Vary-Parameters
Meta-Geo-Continent
X-ND-Cache
X-Powered-By-VTEX-Cache
X-Proto
Wxu-Next-Region
Wxu-Next-Hostname
Sslversion
X-A
X-Rojux
X-BCube-Filmed-By
X-SRCache-Key
X-ScT
Surrogated-Key
X-SB
X-Request-Start
Vix-Hermes-Req-Id
X-Varnish-Hostname
Wxu-Next-Commit
X-Vdms-Path
X-Pubstack
T-Server
X-Bc-Bl
Server-Host
X-A-Ccd
Rendered-Blocks
X-A-Dam
X-A-Dgt
X-UA-Device-Type
X-Origin-Expires
X-Org
X-Aed
X-A-Wwc
X-TIM-N
Req-ID
X-Bip
X-Platform
X-Policy
X-Bl-Debug
X-A-Dcw
X-Thanos
X-Block-Status
X-Varnish-Beresp-Ttl
X-TT-LOGID
X-NGINX-Cache
X-Origin-Response-Time
Host-ID
X-Debug-Cache-Store
Fastly-SSL
Gh-Request-Id
Ha-Gx-Prefs
HA-Ipaddr
X-AK-Request-ID
X-Backend-Instance
Origin-CC
Origin-EX
X-CGP
Server-Ext
Server-Hostname
X-Cdn-Srv
PFcat
Powered-By
X-Cache-Info
X-Cache-Bucket
Release
X-Cache-TTL-Remaining
Sever-Int
NM-Fastcgi-Cache
X-CUA
X-Amz-Storage-Class
L5d-Success-Class
W
We-Hiring
X-App-Name
X-Auth-Group-Type
X-Csrf-Jwt
X-Core-Value
Ssr
X-Auto-Login
Mail-Subject
X-Debug-Cache-Fetch
X-Fmm-Version
X-PAYTM-SRV-ID
X-Origin-Time
X-Ig-Push-State
X-Varnishpool
X-VarnishDD-TTL
X-ECache
X-Nyt-Route
Fastly-Backend-Name
X-WA-Info
WP-Super-Cache
X-Loc
X-Mvc-Supplant-OutputCached
X-Nginx-Cache-Key
Yak-Timeinfo
XM
X-Scheme
X-Varnish-Director
X-SD-PageType
X-Varnish-Beresp-Status
X-LiteSpeed-Cache-Control
X-Test
X-Ismobilevalue
X-Request-Time
X-RateLimit-Limit-Second
X-ID
X-RateLimit-Remaining-Second
X-Region-Sid
X-Req
X-HS-Content-Campaign-Id
X-NMSegId
X-Var-Ttl
C-Via
Cache-Provider
X-Edge-Server
Content-Script-Type
X-Geo-Header
X-Gdpr
Canary
X-Eu-Site
Cdncip
Cdnsip
Cdn-Request-Time
Cdn-Host
X-Fastly-Cache
CDCHOST
Content-Style-Type
AKAMAI
X-VG-WebCache
X-Via-Fastly
DSUID
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-HN
X-GeoIP
X-Newrelic-Synthetics
X-V-Cache
X-Request-Host
X-DPWN-IS-SECURE
X-ApacheServer
X-Aicache-OS
X-SVT-ORM-VERSION
X-Section
X-Render-Time
X-We-Are-Hiring
X-SVT-ORM-RULES
X-Ec-Custom-Error
X-Varnish-Authentication
X-Wikidot-Static-Cache
X-Micro-Cache
X-Mly-Id
X-GoCache-CacheStatus
X-Location
Odigeo-Trace-Id
X-Human
X-Contensis-Viewer-Groups
X-Ad-Load-Variation
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Backend
X-Wikidot-Backend
X-Proxied-Request
X-BBC-Edge-Cache-Status
X-VG-TLSProxy
X-Pool
X-Cache-Aspx
X-From
X-PERF
X-B3-Trace-ID
X-Acquia-Purge-Cdn-Unconfigured
On-Server
L
Is-Eu
Fastly-GeoIP-CountryCode
Platform
Pramga
Req-Svc-Chain
Redirect-Candidate
Producers
Esi-Enabled
Cluster
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
X-Service
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Click-Count-Error
Click-Count-Action-Start
Cache-Key
RNT-Machine
Machine
X-Access
True-Client-Country-4JS
Web-Mar-Region
Tube-Got-Results
Tube-Return
RNT-Time
Tube-Got-Eval
Tube-Get-Contents
X-Zone
X-AIR-PT
Country-Code
NGX
X-Men
V-Age
X-Fastly-Backend
X-Up
X-Server-IP
X-Custom-Header
X-Sn-Servicetimems
X-CacheTTL
X-NodeID
X-Dc
X-Hash
Debug
Proxy-Firewall
X-Date
X-Slack-Shared-Secret-Outcome
X-Accel-Expires-Debug
X-Slack-Backend
X-Varnish-Hits
X-Pad
X-CACHE-GROUP
X-Varnish-Remaining-TTL
X-Nananana
X-LB-ID
X-Cs
X-DefHash
X-DefElseHash
X-Varnish-CookieHashed-On
Datacenter
X-Varnish-CookieINHashed-On
Mime-Version
Fastly-Drupal-HTML
SID
X-Client-Ip
X-Nf-Request-Id
Pics-Label
X-HOST
X-Refresh
CloudFront-Viewer-Country
X-Depends
Locid
X-Akamai-Transformed
X-Servedbyhost
X-CACHE-AGE
X-VC-TTL
X-Via-Popn
X-Via-Popv
X-HA-Backend
X-VHOST
X-Via-Poph
X-Amz-Meta-Cb-Modifiedtime
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
GeoIP-Latitude
X-M-Log
X-Datadome
X-M-Reqid
X-Cache-FS-Status
X-Cached-By
X-Parent-Response-Time
Ngx-Var-Key
X-Old-Content-Length
X-Presslabs-Stats
X-LiteSpeed-Tag
X-LB-NoCache
X-HITS
X-CS
X-TIME
X-NewRelic-App-Data
Resin-Trace
X-Litespeed-Tag
X-B3-Parentspanid
X-CDN-Cache-Status
X-TH-Server
X-Moov-T
X-Moov-Xdn-Version
Server-Info
Cf-Ipcountry
Fastly-Drupal-Html
X-DynaTrace-JS-Agent
Cdn
X-Wa
Server-ID
GeoIp-Country-Code
Cross-Origin-Embedder-Policy-Report-Only
X-Nc
BehaviorPad-Version
X-ZONE
X-VCache
X-Vgn-Hpd-Reason
NtCoent-Length
X-APP
X-User
X-External-Request-Id
Cf-Device-Type
X-Application
X-IAuth-Set-Uid
X-S-Cookie
X-Destination
FSS-Cache
X-B-Cookie
X-Vc
X-Content-Length
True-Client-IP
Uri
X-Fpc
X-Zen-Fury
X-Esi
X-HostName
X-TX-ID
CDN
X-Varnish-Beresp-TTL
True-Client-Ip
X-Instance-Name
X-Srv
X-Cache-Date
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Dynatrace-Js-Agent
Tcn
X-VServer
Load-Balancing
X-API-Version
X-Route-Name
X-Providence-Cookie
X-Flags
Serverhost
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Oracle-DMS-ECID
X-DynaTrace
X-Segment-20210421
GeoIP-Country-Code
Srv
X-Branch-Name
Request-ID
Hostname
Vc-Max-Age
X-RequestId
X-Dispatch
X-Cdn-Cache-Status
X-Dispatcher-Number
Product
X-NC
X-WA
X-FPC
S-Rt
X-Cdn-Forward
X-Page-View
Ohc-File-Size
X-DataCenter
X-B3-Spanid
X-APP-VERSION
ServerName
X-Webkit-Csp-Report-Only
Type
Geoip-Latitude
Srvid
X-FL-QIT-DEBUG
Server-Id
X-Bug-Bounty
X-Geo
X-Sql-Duration-Ms
X-Http-Reason
X-Lb-Nocache
X-Ckpd-Fst-Backend
X-Irp-Debug
X-Sql-Count
Cl-Cache
X-ServedByHost
CacheControlHeader
DataCenter
X-VCL-Version
X-SIPLIST1
Epwk-X-Cache
Cloudfront-Viewer-Country
Edge-Copy-Time
X-Owner
X-CACHE-KEY
IsBot
X-Via-CDN
X-Via-SSL
Origin-Trial
X-Via-Edge
Ohc-Cache-HIT
WZWS-RAY
X-Cache-Ttl
MIME-Version
X-Correlation-ID
Cross-Origin-Opener-Policy-Report-Only
X-Proxy-CacheRZ
X-Core-Mission
X-Lb-Id
X-Ha-Backend
ServerHost
X-Ua
X-Via-PopH
X-Via-PopN
XkeyRZ
PICS-Label
X-Via-PopV
X-App
Rtss
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-CSRF-TOKEN
X-MSEdge-Features
X-Qloud-Router
X-MSEdge-Flight
X-MiniProfiler-Ids
X-Hit
N-Cache
Lb
X-Vmg-Version
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Service-Response-Time
Sm-Log-Id
X-Acquia-Application-Trace
X-Limited
Warning
Cneonction
User-Agent
X-Fastly-Country-Code
CountryCode
X-Acquia-Site
X-Web-Server
X-Sqd-Ctime
X-Datacenter
X-Sqd-Stime
X-Akamai-Device-Characteristics
X-Amz-Meta-Opti
X-LAGOON
X-Nf-Ats-Version
X-Nf-Language
X-Nf-Country
X-HubSpot-Correlation-Id
X-Litespeed-Cache-Control
X-Requestid
X-IN-APIGATEWAYSSL
X-Akamai-Pragma-Client-IP
Xkeylog
X-Info
X-Proxy-Cache-La3
Xkey-La3
X-IN-APIGATEWAY
X-RAMCache
X-Amz-Meta-S3b-Last-Modified
X-Ramcache
X-Snapshot-Date
Ngx
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-Check-Cacheable
X-Serial
X-Th-Server
X-Dw-Trace-Id