Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
Accept-CH
X-DNS-Prefetch-Control
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Check
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
Upgrade
Status
X-CDN
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
Cf-Edge-Cache
X-Amz-Id-2
X-Via
Host-Header
EagleId
Permissions-Policy
Keep-Alive
Request-Context
X-Cache-Group
X-Backend
X-Robots-Tag
X-UA-Device
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
Xkey
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
X-LiteSpeed-Cache
Grace
X-Server-Powered-By
Allow
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-OneAgent-JS-Injection
P3p
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Dns-Prefetch-Control
X-Cache-Lookup
X-Device
X-WebKit-CSP
EagleEye-TraceId
X-Host
Cf-Railgun
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Server-Id
X-Response-Time
X-Readtime
X-Ruxit-JS-Agent
Surrogate-Control
X-Akam-SW-Version
X-HW
X-Cloud-Trace-Context
Request-Id
X-Node
Content-Location
X-Country
X-Application-Context
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-ASPNET-VERSION
X-Content-Type
X-Trace
X-Clacks-Overhead
Cache-Tag
X-Url
X-Litespeed-Cache
Rating
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-TtlSet
X-Vname
X-PC
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Daa-Tunnel
X-FTR-Request-ID
X-Browser-Type
X-Server-Name
Nginx-Cache
X-Powered-By-Plesk
X-CST
AR-ATIME
AR-Request-ID
AR-SID
AR-PoweredBy
X-Cnection
X-Cache-TTL
Accept-Ch
X-ESI
X-Ac
X-Element-Page-Cache
X-D2id
Edge-Control
Verso
X-GitHub-Request-Id
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-MS-InvokeApp
X-Ser
AR-CACHE
X-Vcap-Request-Id
X-Abt-Application-Version
X-ECACHE
X-Upstream
X-FastCGI-Cache
X-B3-TraceId
X-Navigation-Version
X-Dw-Request-Base-Id
Fastly-Restarts
SPIisLatency
SPRequestDuration
X-Webkit-Csp
X-Mod-Pagespeed
X-Amz-Rid
SPRequestGuid
X-SharePointHealthScore
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Instrumentation
X-Client-IP
X-PDP-UNCACHING-HASH
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Hash
X-ARC
X-Ratelimit-Limit
X-Mg-S
X-Powered-CMS
X-Sol
Pagespeed
X-Middleton-Display
Display
X-NF-Request-ID
S
Edge-Cache-Tag
X-Oneagent-Js-Injection
X-Amzn-Trace-Id
Cache-Status
X-Version
Access-Control-Request-Method
Response
X-Middleton-Response
X-VARITI-CCR
RTSS
X-Varnish-TTL
X-TTL
X-Ratelimit-Remaining
X-Forwarded-For
Realpath
X-Cache-Key
X-T
X-Content-Digest
X-Fastly-Request-ID
Cross-Origin-Resource-Policy
X-Recruiting
X-TraceId
X-Correlation-Id
X-ORACLE-DMS-RID
X-Cached
Fastcgi-Cache
X-Server-ID
X-MSEdge-Ref
X-Shield-Request-Id
Front-End-Https
X-RateLimit-Remaining
MicrosoftSharePointTeamServices
X-Ua-Browser
X-Forwarded-Proto
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
Payment
X-PressLabs-Stats
MS-Author-Via
X-Frontend
X-HS-Cache-Config
X-HS-Content-Id
TP-Cache
Server-Node
Arr-Disable-Session-Affinity
X-Protected-By
X-LLID
Public-Key-Pins
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ruxit-Js-Agent
Count-Hit
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-HS-Combine-CSS
X-Accel-Expires
X-GUploader-UploadID
X-Distributor
X-LB-Cache
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-Origin-Server
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-NODE
X-Newrelic-App-Data
X-FTR-Expires
X-HP-Webp
X-HP-Trace-Id
X-Ezoic-Cdn
X-Jurisdiction
X-Request-Handler-Origin-Region
X-Microsite
X-Www-Served-By
Accept-Charset
X-ORACLE-DMS-ECID
Host
X-Varnish-Server
X-Content-Security-Policy-Report-Only
X-App-Server
X-Cluster-Name
X-Activity-Id
X-AppVersion
Cache-Tags
X-Az
MRF-Tech
Cleartype
Mrf-Cache-Status
X-Amz-Meta-S3cmd-Attrs
Retry-After
X-Varnish-Backend
X-B3-TraceId-Primal
X-Ua-Device
X-Goog-Metageneration
Filterid
Surrogate-Key
X-Unique-Id
Server-Name
X-Ttl
X-Git-Hash
Access-Control-Allow-Method
X-Debug
X-Hits
X-Envoy-Decorator-Operation
X-Load-Cache
X-Upgrade-Enabled
X-NGENIX-Cache
X-Azure-Ref
X-CSRF-Token
X-Geo-Country
X-Logged-In
X-Hostname
X-FB-Debug
TCN
X-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
TP-L2-Cache
X-Tt-Trace-Tag
X-Proxy
X-Tt-Trace-Host
X-Seen-By
Section-Io-Cache
X-Grace
X-Time
X-TT
X-B
X-Request-Guid
DC
X-Cache-Control
Pinterest-Generated-By
Pinterest-Version
X-Revision
X-Pinterest-Rid
X-B3-Sampled
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Contextid
X-Hcs-Proxy-Type
Healthy
X-F-Cache
X-Type
X-Trace-Id
Viewport
X-Fb-Rlafr
Referer-Policy
X-Goog-Stored-Content-Encoding
X-Mobile
X-Goog-Generation
X-N
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
Fastly-SWR
Fastly-SIE
X-XRDS-LOCATION
Paypal-Debug-Id
Content-Disposition
X-DIS-Request-ID
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Page-Id
X-Varnish-Grace
X-Debug-Info
X-Via-JSL
X-Magnolia-Registration
X-Px
X-Origin-Cache
X-Webkit-CSP
Version
X-Amz-Replication-Status
X-Whom
X-Ratelimit-Reset
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Aws-Lambda-Call-Status
X-Content-Options
X-G
X-ProcessESI
X-RemovedCookies
X-UUID
X-Adobe-Content
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Adobe-Loc
X-Rule
X-App-Environment
X-Debug-IsConnected
X-Tumblr-Pixel
X-Debug-IsPreview
X-Node-Name
X-Oracle-Dms-Ecid
X-Template
X-Yottaa-Optimizations
X-Wormhole-Sdk
X-Hl-Ver
X-Wix-Request-Id
X-Datadog-Sampled
X-Yottaa-Metrics
X-Storage
NGB
X-Source
Charset
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Is-Bot
X-NYM-Debug-Backend
X-RTag
MS-CV
X-Cacheable-TTL
X-Instance
X-B-Cache
X-Backend-Name
Ms-Operation-Id
X-Rendered-As
X-Region
X-User-Agent
X-Device-Type
X-Proxy-Cache-Info
X-Signature
X-Varnish-Ttl
X-Environment-Context
Amp-Access-Control-Allow-Source-Origin
X-FW-Serve
GEO-INFO
X-Rid
X-FW-Hash
X-ServerID
X-FW-Version
X-Status
X-FW-Static
X-FW-Dynamic
X-FW-Type
X-FW-Server
Cross-Origin-Window-Policy
Country
X-L-Path
ServerID
X-IPS-LoggedIn
X-Cache-Grace
Countrycode
X-Real-IP
X-EdgeConnect-Cache-Status
X-URL
Akamai-GRN
X-NWS-UUID-VERIFY
X-Cache-Age
X-RM-Cache-TTL
X-Cache-Hit
Front
Liferay-Portal
X-WP-CF-Super-Cache-Active
X-Amzn-Remapped-Content-Length
SRV
X-Framework
X-B3-SpanId
X-Ismobilevalue
X-Language
X-AB
X-Air-Pt
X-Sucuri-ID
X-Sucuri-Cache
OT-Force-Account-Verify
X-Oracle-Dms-Rid
X-Akamai-Request-ID2
X-Servername
X-Content-Powered-By
X-Nf-Request-Id
X-UA
X-Air-Source
X-VC-Cache
From-Origin
X-Air-Trace-Id
X-Air-Hostname
X-VC
Backend
X-WebKit-CSP-Report-Only
Xet-Cookie
X-Mode
X-DataDome
X-SRV
Upgrade-Insecure-Requests
Accept-Language
Refresh
X-Api-Version
X-Handled-By
X-Cache-Time
X-Xrds-Location
X-Cache-Status-Check
Access-Control-Request-Headers
LB
X-HTML-Minification-Powered-By
X-Tt-Logid
X-RID
X-UPSTREAM-Address
Meta-Geo
Filters
X-Rewrite-Enabled
X-JoinUs
X-SaId
X-Rn-Rsrv
Cache
Webcakes-Region
Webcakes-App-Version
X-ECache
Webcakes-App-Name
X-Adobe-Source
X-Cache-Operation
X-R9-Blue-Green-Version
TWC-Privacy
X-Container-Uri
X-Xfnlog-Site
X-Cms-Context
X-RCS-CacheZone
X-Generated-By
X-Provided-By
X-PHP-Host
TWC-Connection-Speed
TWC-Locale-Group
X-Git-Commit
Property-Id
X-Origin-Hint
X-Cache-Rule
X-Labrador-Cache-Channel
X-S
X-Origin-Date
X-Webstats-RespID
X-Tumblr-Pixel-2
X-Hosted-By
ServedBy
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Varnish-Age
TWC-Device-Class
X-Forwarded-Host
X-Loop
X-Logging-Id
X-Locale
Atl-Traceid
X-Fetched-On
Web-Mar-Node
Url
Webserver
X-No-Session
X-ProxyCache-Key
X-Lambda-Id
X-Is-Supported-Browser
X-Cache-Debug
X-Cluster
X-BYPASS-REASON
Section-Io-Id
X-Browser-Name
X-Geo-Region
X-Accel-Version
X-Akamai-Edgescape
X-Is-Mobile
X-Is-Desktop
X-Httpd
X-Is-Tablet
X-Scope-Id
X-Site-Version
X-Nginx-Cache
X-Served-From
X-Reqid
X-Skip-Cache
X-Tb
X-Fastly-Request-Id
X-Web-Node
X-Tncms
X-Redis-Cache
X-Tcp-Rtt
X-Endurance-Cache-Level
X-ProxyCache-Status
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Format
X-VCT
X-Alternate-Cache-Key
Mn-Server-Ip
X-Ms-Request-Id
X-Upstream-Ht
X-Shopify-Stage
X-IPLB-Instance
X-Soup
X-IPLB-Request-ID
X-Upstream-Ct
X-Ms-Version
X-Edge-Location
X-Storefront-Renderer-Rendered
Apigw-Requestid
X-Optimistic-Header
X-Say-TTL
X-Request-URI
X-Origin
X-Director
X-Say-Cacheable
X-Restarts
X-SayCDN-TTL
X-Cache-Host
X-INCAP-ABP
X-Detected-As
X-Frame-Option
X-Proxy-Build
X-Extlb
Xserver
X-AWS-Id
X-RateLimit-Limit
X-VWS-Id
X-Cloudmap
X-Zipkin-Id
Selected-Fe
X-Timing-Wait
X-LJ-Flow-ID
X-Mg-Request-UUID
X-Proxied
X-Routing-Service
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-ShopId
X-ShopId
X-Azure-Ref-OriginShield
X-Vcl-Version
Frame-Options
X-GeoCode
X-GeoCountry
Onion-Location
Expiry
X-Connection-Hash
X-Lagoon
X-CDN-Forward
X-Vcache
WPO-Cache-Message
WPO-Cache-Status
X-Generation-Time
X-CMSURLCustom
Thinkindot-Control
Protected
X-WP-CF-Super-Cache-Cookies-Bypass
X-Thinkindot-L3
Source
TDXMobile
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Shield-Cache-Expires
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-ID
Cdn-Requestid
X-Cache-Expired-At
X-Origin-CC
X-Cdn-Origin
X-Origin-TTL
Fastcgi-Useragent
X-XRDS-Location
X-Cache-Action
X-PHP-Backend
X-Proxy-Cache-Status
Priority
Environment
X-Pass-Why
X-Vercel-Cache
X-Vercel-Id
X-Worker
Uber-Trace-Id
X-GEO
Cache-Hits
X-Rocket-Nginx-Serving-Static
Azure-SiteName
Azure-RegionName
Azure-Version
Azure-InstanceId
Azure-SlotName
X-App-Version
X-TA-CDN-Provider
Node
X-Urbn-Site-Id
Sid
X-Urbn-Context-Path
X-Cluster-Node
Locale
X-Buckets
CF-IPCountry
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestPullCode
X-Aspnetmvc-Version
Cross-Origin-Embedder-Policy
CDN-Cache
CDN-PullZone
CDN-RequestCountryCode
CDN-CachedAt
CDN-EdgeStorageId
X-FB-TRIP-ID
Cache-Tv-Group
X-Tumblr-Pixel-3
X-Cdn
X-RateLimit-Reset
X-Auth-Group-Type
X-Cache-Server
X-Fastcgi-Cache
Alternate-Protocol
AMP-Access-Control-Allow-Source-Origin
DB-Nickname
X-B3-Traceid
X-HITS
X-Tx-Id
X-Pad
X-Server-W
X-A
X-Developer
X-Dispatcher-Server
X-Service
X-DefHash
X-D
A
X-DefElseHash
X-Generated-On
X-Custom-Header
X-Ec-GeoHdr
X-Edge-Server
X-Esi-Check
X-GeoIP-City
X-Fastly-Backend
X-Ec-Fail
X-Ig-Origin-Region
X-Epic-Correlation-Id
X-Bc-Bl
Wxu-Next-Commit
Lang
Magicmarker
Wxu-Next-Hostname
Wxu-Next-Region
X-A-Dcw
X-A-Dam
X-A-Ccd
MD5-Digest
Meta-Geo-Continent
Sslversion
Origin-Agent-Cluster
Rendered-Blocks
Odigeo-Trace-Id
Surrogated-Key
T-Server
Ngx.Var.Host
Gannett-Cam-Experience-Id
X-A-Dgt
Candidate-Md5Url
X-Cache-Id
Cdn-Host
X-Cache-NE
X-Cache-TTL-Remaining
X-Content-Age
X-Conf
Cdn-Request-Time
X-Bl-Debug
DCR-Processing-Time-Ms
X-Aed
X-A-Wwc
DCR-Decision-By
Content-Secure-Policy
X-BCube-Filmed-By
X-Ig-Push-State
X-Core-Value
X-Gzip
X-Origin-Expires
X-Vdms-Version
X-Varnish-Remaining-TTL
X-Org
X-Via-Fastly
X-ND-Cache
X-Viewer-Country
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-ScT
X-SRCache-Key
X-TIM-N
X-Rojux
X-V-Cache
X-Req
X-Origin-Cache-Key
X-Op-Id-All
X-Vtex-Remote-Cache
HostName
User-Cache-Control
X-Level-Front-Cache
Mime-Version
X-DC
X-Client-Ip
Producers
X-Ad-Load-Variation
XM
Req-ID
X-UA-Device-Type
Powered-By
X-Aicache-OS
X-App-Name
X-Test
X-Tb-Optimization-Total-Bytes-Saved
X-Bip
X-Backend-Instance
X-B3-Trace-ID
X-Amz-Storage-Class
X-Acquia-Purge-Cdn-Unconfigured
X-Thanos
X-AK-Request-ID
X-Varnish-Hostname
Tube-Got-Results
X-VG-WebCache
Tube-Return
Ssr
Tube-Got-Eval
X-VTEX-Cache-Time
Tube-Get-Contents
X-VTEX-Cache-Server
V-Age
Vix-Hermes-Req-Id
RNT-Time
X-Varnish-Director
RNT-Machine
X-VarnishDD-TTL
Server-Host
X-SVT-ORM-VERSION
X-Wikidot-Backend
X-VG-TLSProxy
X-Wikidot-Static-Cache
X-Cache-Info
X-NMSegId
X-Gen-Mode
X-Mvc-Supplant-Cachable
X-Mly-Id
X-Micro-Cache
X-Node-Id
X-Gdpr
X-FC-Vary-Parameters
X-Fmm-Version
X-NodeID
X-Forwarded-Site
X-Men
X-Geo-Header
Platform
X-HN
X-Hnp-Log
X-HS-Content-Campaign-Id
X-GoCache-CacheStatus
X-GeoIP-Region-Code
X-GeoIP
X-LSADC-Cache
X-Loc
X-GeoIP-Country-Code
X-Nyt-Route
X-Origin-Response-Time
X-Clientip
X-Cdn-Srv
X-Scheme
X-SB
X-Region-Sid
X-SD-PageType
X-Jobs
X-Cache-Bucket
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Server-IP
X-RateLimit-Remaining-Second
X-Debug-Cache-Fetch
X-DPWN-IS-SECURE
X-Platform
X-PAYTM-SRV-ID
X-Origin-Time
X-Policy
X-Powered-By-VTEX-Cache
X-Debug-Cache-Store
X-RateLimit-Limit-Second
X-Pubstack
X-Proto
X-Block-Status
X-CacheTTL
Esi-Enabled
Edge-Cache
Country-Code
Fastly-Backend-Name
Fastly-SSL
Is-Eu
Host-ID
Click-Count-Error
Click-Count-Action-Start
Adler-Geo
X-Dc
AKAMAI
Cache-Provider
Cdnsip
Cdncip
NM-Fastcgi-Cache
X-LiteSpeed-Cache-Control
Origin
PFcat
X-NGINX-Cache
Apple-News-Services-Handled
Apple-News-Services-Host
X-Contensis-Viewer-Groups
X-CUA
Proxy-Firewall
X-Section
X-Date
X-Request-Time
Apple-News-Services-Request-Url
Release
X-Cache-Aspx
Origin-EX
Origin-CC
CDCHOST
X-Mvc-Supplant-OutputCached
X-Depends
X-CGP
C-Via
Apple-News-Services-Parsed-Url
X-Cache-FS-Status
X-WA-Info
X-We-Are-Hiring
Yak-Timeinfo
X-Slack-Shared-Secret-Outcome
X-Hash
X-Human
X-Var-Ttl
X-Varnish-Authentication
X-Varnish-Beresp-Status
X-Slack-Backend
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
X-Ec-Custom-Error
Fusion-Deployment-Id
Fusion-Content-Source
X-Fastly-Cache
Fusion-Content-Id
X-Eu-Site
Req-Svc-Chain
X-Csrf-Jwt
Fastly-GeoIP-CountryCode
Server-Hostname
X-Proxied-Request
Gh-Request-Id
X-Accel-Expires-Debug
X-Access
On-Server
Server-Ext
X-Request-Start
Ha-Gx-Prefs
X-Request-Host
L5d-Success-Class
Machine
Mail-Subject
True-Client-Country-4JS
L
Sever-Int
Web-Mar-Region
We-Hiring
W
DSUID
HA-Ipaddr
Content-Style-Type
X-BBC-Edge-Cache-Status
Content-Script-Type
X-Auto-Login
Cluster
X-Varnish-Beresp-Ttl
X-Nginx-Cache-Key
X-Location
Cache-Key
Canary
X-Device-Os
NGX
X-Pool
Pramga
X-Varnishpool
X-AIR-PT
Server-Info
X-Varnish-Hits
X-Zone
X-Cs
X-From
BehaviorPad-Version
X-NCache
Debug
X-Up
Redirect-Candidate
X-LB-ID
CDN-RequestId
X-Akamai-Transformed
X-Jungle-Id
X-Refresh
X-MP-GENERATED-AT
X-APP
X-Tec-Api-Version
X-Tec-Api-Origin
X-CACHE-AGE
SID
X-Tec-Api-Root
X-Vdms-Path
CloudFront-Viewer-Country
X-Via-Popv
Pics-Label
X-Via-Popn
X-Via-Poph
X-HA-Backend
X-Cache-Backend
WP-Super-Cache
Fastly-Drupal-HTML
X-Parent-Response-Time
X-Servedbyhost
X-B3-Parentspanid
GeoIP-Latitude
X-VHOST
X-Content-Length
X-Uri
X-Datadome
Fastly-Drupal-Html
X-Litespeed-Tag
X-Nananana
X-Nc
X-ApacheServer
X-Render-Time
X-Newrelic-Synthetics
X-LB-NoCache
X-PERF
X-M-Log
X-M-Reqid
X-VC-TTL
X-CDN-Cache-Status
Datacenter
X-CS
X-CACHE-KEY
X-LiteSpeed-Tag
X-Cached-By
Vc-Max-Age
X-DynaTrace-JS-Agent
X-Dispatcher-Number
X-RequestId
NtCoent-Length
X-Wa
Server-ID
Resin-Trace
X-ZONE
GeoIp-Country-Code
Product
Locid
Cdn
X-Amz-Meta-Cb-Modifiedtime
X-B3-Spanid
X-Original-Request-Id
X-Varnish-Beresp-TTL
X-Response-Served-From
X-VCache
X-IAuth-Set-Uid
FSS-Cache
X-Ckpd-Fst-Backend
X-Fpc
X-TT-LOGID
X-NewRelic-App-Data
X-Bug-Bounty
True-Client-Ip
Serverhost
Srv
Uri
X-Esi
True-Client-IP
X-Old-Content-Length
X-HostName
S-Rt
Cf-Ipcountry
X-SERVER-NAME
X-TX-ID
X-Nf-Country
X-Nf-Language
X-Nf-Ats-Version
CDN
X-HubSpot-Correlation-Id
ServerName
Ngx-Var-Key
X-FPC
X-Dynatrace-Js-Agent
GeoIP-Country-Code
Tcn
X-Vgn-Hpd-Reason
X-Oracle-DMS-ECID
X-Cdn-Cache-Status
X-Srv
X-TIME
X-Cdn-Forward
X-Platform-Router
X-Platform-Cluster
X-WA
X-Platform-Processor
X-Moov-T
X-TH-Server
X-Moov-Xdn-Version
X-Webkit-Csp-Report-Only
Request-ID
X-Dispatch
X-Akamai-Device-Characteristics
User-Agent
Server-Id
CacheControlHeader
X-Vc
X-APP-VERSION
Cf-Device-Type
X-Vmg-Version
X-Gamma-Serve
X-Info
X-NC
ServerHost
Hostname
X-COUNTRY
Geoip-Latitude
X-S-Cookie
X-B-Cookie
Cross-Origin-Embedder-Policy-Report-Only
X-User
X-Lb-Nocache
X-Destination
X-External-Request-Id
Xc-Version
Srvid
X-Application
X-FL-QIT-DEBUG
X-Hit
X-Presslabs-Stats
X-Zen-Fury
Expect-Staple
X-Geo
Ohc-File-Size
X-Cache-Date
X-ServedByHost
PICS-Label
X-Via-PopH
Origin-Trial
X-Ha-Backend
X-Via-PopN
X-Amz-Meta-Opti
X-Sigma-Backend
X-Rocket-Build-Number
X-Sigma
X-Via-PopV
X-Instance-Name
Cneonction
Cloudfront-Viewer-Country
X-VCL-Version
X-API-Version
Epwk-X-Cache
X-Segment-20210421
X-VServer
X-Limited
X-V
Permission-Policy
X-Rollout
X-Platform-Server
X-New
X-App
X-Eligible
WZWS-RAY
X-Akamai-Pragma-Client-IP
X-Correlation-ID
X-Branch-Name
X-Ua
X-Srcache-Fetch-Status
Rtss
X-Srcache-Store-Status
X-MiniProfiler-Ids
N-Cache
X-Check-Cacheable
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Sqd-Ctime
X-Proxy-CacheRZ
X-Lb-Id
X-Serial
XkeyRZ
X-Sqd-Stime
Lb
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-DataCenter
X-MSEdge-Flight
X-MSEdge-Features
Timeexpire
X-ElasticPress-Query
X-Internal-TTL
Cmstype
Cmsid
WebServer
X-Web-Server
X-Ftr-Request-Id
Ohc-Cache-HIT
Sm-Log-Id
Ngx
X-Fastly-Backend-Reqs
X-Datacenter
X-Acquia-Application-Trace
X-Acquia-Site
X-Service-Response-Time
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
DataCenter
X-LAGOON
X-CSRF-TOKEN
Servername
CountryCode
Load-Balancing
X-Litespeed-Cache-Control
Type
Fl-Custom-Application
X-VTEX-Cache-Backend-Header-Time
Warning
X-RAMCache
X-VTEX-Cache-Backend-Connect-Time
X-Th-Server
X-Via-CDN
X-Via-Edge
X-Via-SSL
X-Traceid
X-EC-Lua
X-Snapshot-Date
Edge-Copy-Time
X-Requestid
X-DynaTrace
X-Sorting-Hat-Shopid
X-IN-APIGATEWAYSSL
X-Sorting-Hat-Podid
X-Shopid
X-Origin-Upstream-Status
X-Shardid
X-IN-APIGATEWAY
X-Dw-Trace-Id
X-Amz-Meta-Sha256
X-Amz-Meta-S3b-Last-Modified
Wpo-Cache-Status
Wpo-Cache-Message
X-Udemy-Cache-App-Namespace
X-Ramcache