Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-Ua-Compatible
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
CF-Ray
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
X-Age
Permissions-Policy
X-Vhost
X-Amz-Version-Id
Allow
X-Dns-Prefetch-Control
X-Dispatcher
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Host
X-Server-Id
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Litespeed-Cache
X-Node
Content-Location
X-Application-Context
X-Nginx-Cache-Status
X-CST
X-Nginx-Upstream-Cache-Status
X-NWS-LOG-UUID
X-Ruxit-JS-Agent
X-Country
Service-Worker-Allowed
X-Country-Code
X-Url
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Oneagent-Js-Injection
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Times
X-FTR-Request-ID
X-PC
X-TtlSet
X-Vname
X-Daa-Tunnel
X-Server-Name
X-Webkit-Csp
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-ESI
X-Cnection
X-Upstream
Edge-Control
X-ECACHE
X-MS-InvokeApp
X-D2id
X-GitHub-Request-Id
X-Element-Page-Cache
X-Ac
Verso
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Revision
X-Aws-Lambda-Call-Status
AR-SID
AR-PoweredBy
AR-ATIME
AR-Request-ID
Accept-Ch-Lifetime
X-Ruxit-Js-Agent
X-FastCGI-Cache
X-Ser
X-Vcap-Request-Id
X-Navigation-Version
X-Cache-TTL
X-Abt-Application-Version
X-B3-TraceId
X-Mod-Pagespeed
SPRequestDuration
SPIisLatency
AR-CACHE
SPRequestGuid
X-SharePointHealthScore
X-Dw-Request-Base-Id
X-Amz-Rid
Fastly-Restarts
X-NF-Request-ID
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
Pagespeed
X-Middleton-Display
Display
X-Sol
X-Client-IP
Edge-Cache-Tag
X-Mg-S
X-Cache-Key
X-Edge-Location-Klb
S
X-Kinsta-Cache
X-Powered-CMS
X-Middleton-Response
Response
X-Amzn-Trace-Id
X-RateLimit-Remaining
X-VARITI-CCR
Cache-Status
Access-Control-Request-Method
X-Version
X-Goog-Hash
X-Fastly-Request-ID
X-ARC
RTSS
X-Content-Digest
X-TraceId
X-Forwarded-For
Cross-Origin-Resource-Policy
X-Recruiting
X-T
Realpath
X-Varnish-TTL
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Correlation-Id
X-MSEdge-Ref
MS-Author-Via
Front-End-Https
X-Ratelimit-Limit
Fastcgi-Cache
X-Cached
X-Ttl
Content-MD5
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Ua-Browser
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
Server-Node
Payment
X-PDP-UNCACHING-HASH
X-Request-Processing-Time
X-Request-Received
X-Protected-By
X-LLID
X-Frontend
Public-Key-Pins
MicrosoftSharePointTeamServices
X-Shield-Request-Id
X-HS-Combine-CSS
Arr-Disable-Session-Affinity
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Origin-Cache-Key
TP-Cache
X-Forwarded-Proto
X-Distributor
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Kong-Proxy-Latency
X-Accel-Expires
X-Kong-Upstream-Latency
X-FTR-Expires
X-Server-ID
Count-Hit
X-GUploader-UploadID
X-TTL
X-Ratelimit-Remaining
X-Origin-Server
X-LB-Cache
X-Ezoic-Cdn
X-ORACLE-DMS-RID
X-Hits
X-Microsite
X-Request-Handler-Origin-Region
X-Content-Security-Policy-Report-Only
Host
X-Varnish-Backend
X-Activity-Id
X-Cluster-Name
X-Ua-Device
X-AppVersion
X-Az
Mrf-Cache-Status
Cache-Tags
MRF-Tech
X-B3-TraceId-Primal
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Varnish-Server
X-Www-Served-By
Retry-After
Accept-Charset
X-App-Server
X-Amz-Meta-S3cmd-Attrs
X-Hostname
X-PressLabs-Stats
Server-Name
X-Geo-Country
X-NGENIX-Cache
Cleartype
X-Oracle-Dms-Ecid
X-NODE
X-DIS-Request-ID
X-Envoy-Decorator-Operation
Referer-Policy
X-Id
X-Newrelic-App-Data
X-Goog-Metageneration
X-Upgrade-Enabled
TP-L2-Cache
X-Seen-By
X-CSRF-Token
X-Git-Hash
X-Azure-Ref
X-Amz-Apigw-Id
X-Amzn-RequestId
X-RateLimit-Limit
X-F-Cache
X-Hcs-Proxy-Type
Access-Control-Allow-Method
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Load-Cache
X-Tt-Trace-Host
TCN
X-Tt-Trace-Tag
X-Proxy
X-Unique-Id
X-Grace
Filterid
X-Debug-Info
X-Px
X-Revision
X-Trace-Id
Section-Io-Cache
Paypal-Debug-Id
Healthy
X-Cache-Control
X-Request-Guid
X-FB-Debug
X-B3-Sampled
X-B
DC
X-Type
X-Contextid
X-TT
X-Fb-Rlafr
X-Page-Id
X-Oracle-Dms-Rid
X-N
X-Logged-In
X-Mobile
X-ORACLE-DMS-ECID
Viewport
X-XRDS-LOCATION
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Whom
X-Varnish-Ttl
X-Debug
X-Template
Charset
Fastly-SIE
Fastly-SWR
X-Language
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Time
X-Cache-Grace
X-Content-Options
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Webkit-CSP
Version
Content-Disposition
X-Wix-Request-Id
X-Via-JSL
X-RateLimit-Reset
X-EdgeConnect-Cache-Status
X-App-Environment
X-Magnolia-Registration
X-Varnish-Grace
X-B-Cache
X-Signature
X-Node-Name
X-Amzn-Remapped-Content-Length
X-ProcessESI
X-B3-SpanId
SRV
X-RemovedCookies
VIX-Pulpo-Node
X-Origin-Cache
VIX-Pulpo-Upstream-Status
X-Debug-IsConnected
X-Rule
X-Tumblr-User
X-Debug-IsPreview
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
SD-X-WS
X-Hl-Ver
X-Yottaa-Metrics
X-G
X-Yottaa-Optimizations
X-Backend-Name
X-Datadog-Sampled
X-Rid
X-FW-Dynamic
X-Device-Type
X-FW-Hash
X-FW-Serve
X-FW-Server
X-Amz-Replication-Status
X-Adobe-Loc
MS-CV
Ms-Operation-Id
ServerID
X-Adobe-Content
X-FW-Static
X-FW-Type
X-RTag
X-Storage
X-UUID
X-FW-Version
X-Instance
X-Rendered-As
NGB
X-User-Agent
X-Cacheable-TTL
X-Is-Bot
X-IPS-LoggedIn
X-NYM-Debug-Backend
X-Proxy-Cache-Info
Country
X-Region
GEO-INFO
X-Environment-Context
X-L-Path
X-Status
Liferay-Portal
X-Cache-Hit
X-Source
X-NWS-UUID-VERIFY
X-ServerID
X-Real-IP
X-Cache-Age
Surrogate-Key
Akamai-GRN
X-Sucuri-ID
X-Servername
X-Sucuri-Cache
Countrycode
X-WP-CF-Super-Cache-Active
OT-Force-Account-Verify
Cross-Origin-Window-Policy
Amp-Access-Control-Allow-Source-Origin
From-Origin
X-VC-Cache
X-UA
X-WebKit-CSP-Report-Only
X-RM-Cache-TTL
Backend
Upgrade-Insecure-Requests
Front
X-INCAP-ABP
X-Framework
X-Mode
X-Xrds-Location
X-Air-Pt
Frame-Options
Refresh
X-Cache-Time
X-AB
X-Air-Hostname
X-Akamai-Request-ID2
X-HTML-Minification-Powered-By
Xet-Cookie
X-DataDome
X-Air-Source
X-Air-Trace-Id
X-Content-Powered-By
X-Buckets
X-Edge-Location
Url
X-Handled-By
X-Wormhole-Sdk
X-CDN-Forward
X-Endurance-Cache-Level
Webserver
X-Rn-Rsrv
X-RCS-CacheZone
X-AWS-Id
X-Reqid
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Origin-CC
X-Origin-TTL
X-LJ-Flow-ID
X-No-Session
Filters
X-Vcache
X-Cluster
X-SaId
X-Origin-Date
X-VWS-Id
X-Akamai-Edgescape
X-Azure-Ref-OriginShield
X-JoinUs
X-Xfnlog-Site
Meta-Geo
X-IPLB-Request-ID
Webcakes-Region
X-Cache-Operation
X-Cache-Rule
X-Tumblr-Pixel-2
X-IPLB-Instance
X-SRV
X-Generation-Time
Access-Control-Request-Headers
X-Provided-By
X-PHP-Host
X-Origin-Hint
ServedBy
X-Container-Uri
X-Labrador-Cache-Channel
X-R9-Blue-Green-Version
Property-Id
X-Webstats-RespID
Mn-Server-Ip
X-Drupal-Cache-Tags
X-Fetched-On
Webcakes-App-Name
X-Ms-Version
Webcakes-App-Version
X-Ms-Request-Id
X-Git-Commit
TWC-Privacy
TWC-Device-Class
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-Country
TWC-GeoIP-LatLong
WPO-Cache-Status
WPO-Cache-Message
X-Extlb
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
Thinkindot-Control
Web-Mar-Node
X-Adobe-Source
X-Accel-Version
Section-Io-Id
X-BYPASS-REASON
X-Drupal-Cache-Contexts
Atl-Traceid
X-CMSURLCustom
X-Cms-Context
X-Cache-Debug
X-Cloudmap
X-Hosted-By
X-Logging-Id
X-Scope-Id
X-Thinkindot-L3
X-Shield-Cache-Expires
X-Redis-Cache
X-Routing-Service
X-Web-Node
X-Varnish-Cache-Hits
X-Restarts
X-ProxyCache-Status
X-VCT
X-Zipkin-Id
X-Cache-Status-Check
X-Served-From
X-ProxyCache-Key
X-Proxied
X-Cdn-Origin
X-Upstream-Ht
Apigw-Requestid
X-Upstream-Ct
X-Frame-Option
X-Director
X-Format
X-Forwarded-Host
X-Proxy-Build
Selected-Fe
X-Varnish-Age
Cache
X-SayCDN-TTL
X-Locale
X-Skip-Cache
X-Site-Version
X-Timing-Wait
X-Lambda-Id
X-Soup
X-VC
X-Loop
X-Say-Cacheable
X-Say-TTL
X-Tncms
X-Httpd
X-Tb
X-Cache-Host
X-Browser-Name
X-Alternate-Cache-Key
X-Nginx-Cache
X-S
X-ShardId
X-Origin
X-Storefront-Renderer-Rendered
X-Tcp-Rtt
X-RID
Xserver
X-Sorting-Hat-ShopId
X-Is-Desktop
X-Is-Supported-Browser
X-Is-Tablet
X-Sorting-Hat-PodId
X-GeoCountry
Accept-Language
X-ShopId
X-Is-Mobile
X-Detected-As
X-Varnish-Beresp-Grace
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Geo-Region
X-Shopify-Stage
X-GeoCode
X-XRDS-Location
Cache-Hits
X-Worker
X-Generated-By
X-Vercel-Id
X-Vercel-Cache
X-Rocket-Nginx-Serving-Static
X-Lagoon
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-SiteName
Azure-InstanceId
X-B3-Traceid
Source
Node
X-Optimistic-Header
X-WP-CF-Super-Cache-Cookies-Bypass
CDN-RequestId
CDN-PullZone
CDN-Cache
LB
CDN-RequestCountryCode
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestPullSuccess
CDN-RequestPullCode
X-Request-URI
CDN-Uid
Protected
X-Pass-Why
Fastcgi-Useragent
Cross-Origin-Embedder-Policy
X-App-Version
X-Vcl-Version
X-Tumblr-Pixel-3
X-Connection-Hash
Expiry
Alternate-Protocol
X-GEO
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Cache-Server
X-Ratelimit-Reset
X-Cache-Expired-At
DB-Nickname
X-TA-CDN-Provider
AMP-Access-Control-Allow-Source-Origin
Onion-Location
X-Jobs
X-Server-W
CF-IPCountry
X-Fastly-Request-Id
Environment
Priority
X-Fastcgi-Cache
X-Response-Served-From
X-Api-Version
Uber-Trace-Id
X-Original-Request-Id
X-Proxy-Cache-Status
Sid
X-LSADC-Cache
X-Cache-Action
X-Cluster-Node
X-PHP-Backend
User-Cache-Control
X-MP-GENERATED-AT
X-DC
X-TT-LOGID
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-Tx-Id
X-Mg-Request-UUID
X-Uri
HostName
WP-Super-Cache
X-Nf-Request-Id
X-FB-TRIP-ID
X-Developer
T-Server
Sslversion
A
X-Proto
Surrogated-Key
Wxu-Next-Commit
X-Rojux
X-A-Dgt
X-SB
X-A-Wwc
X-ScT
X-A-Dcw
X-A-Ccd
Wxu-Next-Hostname
X-Powered-By-VTEX-Cache
Wxu-Next-Region
X-Generated-On
X-A
Vix-Hermes-Req-Id
Server-Host
X-Origin-Expires
Lang
Fusion-Component-Id
Magicmarker
Edge-Cache
Meta-Geo-Continent
MD5-Digest
Fusion-Content-Id
Fusion-Content-Source
X-Org
X-Op-Id-All
Gannett-Cam-Experience-Id
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
DCR-Processing-Time-Ms
DCR-Decision-By
X-NCache
X-Gen-Mode
Candidate-Md5Url
Cache-Tv-Group
X-Aed
Rendered-Blocks
X-Platform
Origin-Agent-Cluster
Content-Secure-Policy
X-NMSegId
Ngx.Var.Host
NM-Fastcgi-Cache
Origin
X-ND-Cache
X-Mvc-Supplant-Cachable
X-A-Dam
X-Ec-Fail
X-BCube-Filmed-By
X-Ec-GeoHdr
X-TIM-N
X-Vdms-Version
X-Test
X-Gzip
X-Bc-Bl
X-GeoIP-City
X-UA-Device-Type
X-Bl-Debug
X-Epic-Correlation-Id
X-Esi-Check
X-Cache-NE
X-Varnish-Hostname
X-Hnp-Log
X-Cache-Id
X-Block-Status
X-Ig-Origin-Region
X-Vdms-Path
X-FC-Vary-Parameters
X-GeoIP
X-Jungle-Id
X-Level-Front-Cache
X-SRCache-Key
X-Viewer-Country
X-Content-Age
X-Conf
X-D
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Vtex-Remote-Cache
X-Device-Os
X-Dispatcher-Server
X-LiteSpeed-Cache-Control
X-Varnish-Beresp-Ttl
X-Origin-Response-Time
X-URL
X-Client-Ip
X-NGINX-Cache
Mail-Subject
X-HS-Content-Campaign-Id
X-Clientip
Origin-CC
Origin-EX
Host-ID
X-Edge-Server
PFcat
X-Cdn-Srv
X-Nyt-Route
X-Core-Value
X-Nginx-Cache-Key
L5d-Success-Class
X-Node-Id
X-HN
X-CGP
Server-Hostname
X-Backend-Instance
X-Auto-Login
X-Fmm-Version
X-From
We-Hiring
HA-Ipaddr
X-Gdpr
X-Forwarded-Site
X-Csrf-Jwt
X-GeoIP-Region-Code
X-Amz-Storage-Class
X-Geo-Header
X-ApacheServer
X-Loc
X-Auth-Group-Type
X-App-Name
W
X-Fastly-Cache
Req-ID
X-Mvc-Supplant-OutputCached
Server-Ext
X-Cache-Info
X-Eu-Site
Powered-By
Release
X-AK-Request-ID
X-Cache-Bucket
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Ssr
X-GeoIP-Country-Code
Sever-Int
X-Bip
X-Cache-TTL-Remaining
Cdncip
X-Request-Start
X-Req
X-Request-Time
X-Scheme
Ha-Gx-Prefs
X-Render-Time
X-RateLimit-Remaining-Second
C-Via
Cache-Provider
AKAMAI
X-Service
X-RateLimit-Limit-Second
X-Zone
X-ECache
XM
Cdn-Requestid
X-Policy
X-Pubstack
X-Tt-Logid
X-Via-Fastly
X-VG-WebCache
X-Thanos
X-V-Cache
X-Varnish-Director
X-VarnishDD-TTL
Canary
X-SD-PageType
Cdnsip
Fastly-Backend-Name
Cdn-Request-Time
Content-Style-Type
X-Origin-Time
Content-Script-Type
X-PERF
X-PAYTM-SRV-ID
Cdn-Host
Esi-Enabled
Fastly-SSL
CDCHOST
X-ID
X-Varnish-Beresp-Status
X-Tb-Optimization-Total-Bytes-Saved
X-Var-Ttl
X-Cache-Aspx
X-Varnish-Authentication
X-Cache-Backend
X-BBC-Edge-Cache-Status
Pramga
X-Location
X-Section
X-Aicache-OS
X-Fastly-Backend
X-Sn-Servicetimems
X-Ig-Push-State
Country-Code
X-Human
DSUID
X-WA-Info
L
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-CUA
Fastly-GeoIP-CountryCode
X-We-Are-Hiring
X-Contensis-Viewer-Groups
Machine
X-CacheTTL
Gh-Request-Id
X-Varnishpool
X-Hash
Is-Eu
X-VG-TLSProxy
Yak-Timeinfo
X-B3-Trace-ID
X-Mly-Id
X-Ad-Load-Variation
True-Client-Country-4JS
X-Pool
X-Proxied-Request
Tube-Get-Contents
Tube-Got-Eval
V-Age
X-Men
X-Micro-Cache
Tube-Return
Adler-Geo
Apple-News-Services-Handled
Cache-Key
Platform
Redirect-Candidate
Producers
Req-Svc-Chain
RNT-Machine
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
RNT-Time
Click-Count-Action-Start
Tube-Got-Results
On-Server
X-Access
Cluster
Click-Count-Error
X-Acquia-Purge-Cdn-Unconfigured
Web-Mar-Region
X-Region-Sid
X-AIR-PT
X-Newrelic-Synthetics
NGX
X-SVT-ORM-RULES
X-Date
X-Wikidot-Static-Cache
X-Accel-Expires-Debug
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
Proxy-Firewall
X-Wikidot-Backend
X-GoCache-CacheStatus
X-Request-Host
X-Up
X-SVT-ORM-VERSION
X-Server-IP
Odigeo-Trace-Id
Datacenter
X-Dc
X-COUNTRY
Debug
X-Varnish-Hits
X-Custom-Header
X-NodeID
X-Ismobilevalue
SID
X-Akamai-Transformed
X-CACHE-GROUP
X-Cs
Locid
X-Nananana
Fastly-Drupal-HTML
X-Refresh
X-LB-ID
X-Pad
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-HA-Backend
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-DefElseHash
X-DefHash
X-Amz-Meta-Cb-Modifiedtime
Pics-Label
CloudFront-Viewer-Country
X-Platform-Cluster
X-Platform-Router
X-Platform-Processor
Mime-Version
X-VHOST
X-Servedbyhost
X-CACHE-AGE
X-Depends
X-LiteSpeed-Tag
Ngx-Var-Key
X-Datadome
X-Old-Content-Length
GeoIP-Latitude
X-VC-TTL
X-Cached-By
X-M-Reqid
X-M-Log
X-Presslabs-Stats
X-Cache-FS-Status
X-Parent-Response-Time
X-LB-NoCache
X-TH-Server
X-Moov-T
X-CDN-Cache-Status
X-Moov-Xdn-Version
X-B3-Parentspanid
X-TIME
Cross-Origin-Embedder-Policy-Report-Only
X-CS
GeoIp-Country-Code
Server-ID
Resin-Trace
Cdn
Cf-Ipcountry
X-DynaTrace-JS-Agent
Fastly-Drupal-Html
X-Litespeed-Tag
X-Nc
X-Wa
Server-Info
NtCoent-Length
X-B-Cookie
X-VCache
X-Vgn-Hpd-Reason
X-Destination
X-HITS
X-External-Request-Id
X-User
Cf-Device-Type
X-S-Cookie
X-Application
BehaviorPad-Version
True-Client-IP
X-Vc
X-APP
FSS-Cache
X-Zen-Fury
Uri
X-Fpc
X-NewRelic-App-Data
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Route-Name
X-Esi
X-Sigma-Backend
X-Rocket-Build-Number
X-IAuth-Set-Uid
X-Cache-Date
X-Sigma
X-Instance-Name
CDN
X-TX-ID
X-HostName
X-ZONE
X-API-Version
True-Client-Ip
X-DynaTrace
X-Dynatrace-Js-Agent
X-Varnish-Beresp-TTL
X-Srv
X-Content-Length
X-VServer
X-Segment-20210421
X-Branch-Name
Load-Balancing
Tcn
X-Oracle-DMS-ECID
X-Page-View
GeoIP-Country-Code
X-HOST
Hostname
S-Rt
Serverhost
Srv
Ohc-File-Size
Request-ID
X-Dispatch
X-Dispatcher-Number
X-Cdn-Cache-Status
X-DataCenter
X-WA
X-NC
X-FPC
X-Cdn-Forward
Product
X-RequestId
Type
Vc-Max-Age
X-Sql-Duration-Ms
X-APP-VERSION
X-Http-Reason
X-B3-Spanid
X-Sql-Count
Geoip-Latitude
X-Webkit-Csp-Report-Only
X-Irp-Debug
X-FL-QIT-DEBUG
Srvid
Server-Id
X-Lb-Nocache
X-SERVER-NAME
Cl-Cache
X-Geo
X-Via-SSL
Edge-Copy-Time
WZWS-RAY
X-Owner
X-Via-Edge
X-ServedByHost
ServerName
X-CSRF-TOKEN
X-Via-CDN
X-SIPLIST1
X-Bug-Bounty
DataCenter
IsBot
X-Ckpd-Fst-Backend
CountryCode
X-VCL-Version
Epwk-X-Cache
X-Core-Mission
Cloudfront-Viewer-Country
Ohc-Cache-HIT
MIME-Version
Cross-Origin-Opener-Policy-Report-Only
XkeyRZ
X-Proxy-CacheRZ
Origin-Trial
CacheControlHeader
X-Cache-Ttl
X-Hit
X-App
X-Correlation-ID
X-Qloud-Router
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-Ha-Backend
X-Ua
PICS-Label
N-Cache
X-Srcache-Store-Status
Rtss
X-Srcache-Fetch-Status
X-MiniProfiler-Ids
X-Lb-Id
X-Amz-Meta-Opti
X-MSEdge-Features
ServerHost
X-MSEdge-Flight
X-Fastly-Country-Code
Lb
X-Sqd-Stime
X-Acquia-Application-Trace
X-Service-Response-Time
X-Datacenter
Warning
X-Sqd-Ctime
Sm-Log-Id
X-Web-Server
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Litespeed-Cache-Control
X-LAGOON
X-Vmg-Version
X-Akamai-Device-Characteristics
X-Limited
X-Amz-Meta-Sha256
X-IN-APIGATEWAY
X-Dw-Trace-Id
X-Udemy-Cache-App-Namespace
X-Amz-Meta-S3b-Last-Modified
User-Agent
Cneonction
X-IN-APIGATEWAYSSL
X-CF-Lambda-Fn
Xkeylog
X-Cache-Type
X-Cdn-Request-ID
X-CF-Lambda-Version
Xkey-La3
X-Proxy-Cache-La3
Akamai-Cache-Status
Expect-Staple
X-Orig-Expires
X-Requestid
X-Akamai-Pragma-Client-IP
X-Ramcache
X-Snapshot-Date
X-Tenant
Ngx
X-Th-Server
X-Serial
X-RAMCache
X-Forwarded-Path
X-Check-Cacheable
X-Shop-Environment