Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-Ua-Compatible
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
X-Age
Permissions-Policy
X-Vhost
X-Amz-Version-Id
Allow
X-Dns-Prefetch-Control
X-Dispatcher
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
P3p
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
X-Host
EagleEye-TraceId
X-Server-Id
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
X-Litespeed-Cache
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Application-Context
X-Ruxit-JS-Agent
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-CST
X-NWS-LOG-UUID
X-Country
Service-Worker-Allowed
X-Country-Code
X-Url
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Oneagent-Js-Injection
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Times
X-FTR-Request-ID
X-PC
X-Server-Name
X-TtlSet
X-Vname
X-Daa-Tunnel
X-Webkit-Csp
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-Cnection
X-ESI
X-Upstream
Edge-Control
X-GitHub-Request-Id
X-MS-InvokeApp
X-D2id
X-Element-Page-Cache
Verso
X-Ac
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Aws-Lambda-Call-Status
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-ECACHE
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Ser
X-Vcap-Request-Id
X-Navigation-Version
X-Cache-TTL
X-Abt-Application-Version
X-B3-TraceId
X-Mod-Pagespeed
SPRequestDuration
SPIisLatency
X-Ruxit-Js-Agent
AR-CACHE
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
Fastly-Restarts
X-NF-Request-ID
X-Client-IP
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
Pagespeed
X-Middleton-Display
Display
X-Sol
X-RateLimit-Remaining
X-Mg-S
Edge-Cache-Tag
S
X-Edge-Location-Klb
X-Cache-Key
X-Kinsta-Cache
X-Powered-CMS
X-Middleton-Response
Response
X-Amzn-Trace-Id
Cache-Status
X-VARITI-CCR
X-Version
Access-Control-Request-Method
X-Goog-Hash
RTSS
X-ARC
X-Content-Digest
X-Fastly-Request-ID
X-TraceId
X-Forwarded-For
X-Recruiting
Cross-Origin-Resource-Policy
X-T
Realpath
X-Varnish-TTL
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Ttl
X-Correlation-Id
X-MSEdge-Ref
MS-Author-Via
Front-End-Https
X-Ratelimit-Limit
X-Cached
Fastcgi-Cache
Content-MD5
X-Ua-Browser
X-HS-Hub-Id
X-FTR-Backend-Server
X-Protected-By
X-FTR-Cache-Status
X-HS-Cache-Config
X-Country-Code-Real
Payment
X-FTR-Backend
X-HS-Content-Id
X-FTR-Balancer
X-Request-Received
X-Request-Processing-Time
X-PDP-UNCACHING-HASH
Server-Node
Public-Key-Pins
X-Frontend
Arr-Disable-Session-Affinity
X-Forwarded-Proto
X-LLID
X-Shield-Request-Id
MicrosoftSharePointTeamServices
X-Origin-Cache-Key
TP-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-HS-Combine-CSS
X-Distributor
X-Accel-Expires
X-Server-ID
X-FTR-Expires
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Count-Hit
X-GUploader-UploadID
X-Hits
X-Origin-Server
X-LB-Cache
X-Ezoic-Cdn
X-ORACLE-DMS-RID
X-Request-Handler-Origin-Region
X-Microsite
X-Content-Security-Policy-Report-Only
X-Activity-Id
X-Az
Host
X-AppVersion
X-TEC-API-ROOT
X-Ua-Device
X-TEC-API-ORIGIN
X-Www-Served-By
X-TEC-API-VERSION
X-PressLabs-Stats
X-TTL
X-Varnish-Backend
X-Cluster-Name
Cache-Tags
Retry-After
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Varnish-Server
X-Ratelimit-Remaining
X-App-Server
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
X-Id
X-Hostname
Server-Name
X-NGENIX-Cache
X-Geo-Country
Cleartype
X-NODE
X-Envoy-Decorator-Operation
X-Newrelic-App-Data
Referer-Policy
X-DIS-Request-ID
X-Goog-Metageneration
X-Upgrade-Enabled
TP-L2-Cache
X-CSRF-Token
X-Seen-By
X-Oracle-Dms-Ecid
X-Azure-Ref
X-Git-Hash
Access-Control-Allow-Method
X-Amz-Apigw-Id
X-Amzn-RequestId
X-RateLimit-Limit
TCN
X-F-Cache
X-CCDN-Origin-Time
X-Load-Cache
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Unique-Id
X-ORACLE-DMS-ECID
X-Tt-Trace-Host
X-Grace
X-Tt-Trace-Tag
X-Px
X-Revision
X-Proxy
Healthy
X-Debug-Info
Filterid
X-Cache-Control
X-Request-Guid
X-Trace-Id
X-XRDS-LOCATION
Section-Io-Cache
Paypal-Debug-Id
X-FB-Debug
X-TT
DC
X-Type
X-B
X-Page-Id
X-Fb-Rlafr
X-Contextid
X-B3-Sampled
X-Oracle-Dms-Rid
X-N
X-Mobile
X-Logged-In
X-WP-CF-Super-Cache-Cache-Control
Viewport
X-WP-CF-Super-Cache
X-Varnish-Ttl
X-Whom
X-Template
X-Debug
Charset
Fastly-SIE
Fastly-SWR
X-Language
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Time
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Datadog-Trace-Id
X-Content-Options
X-Cache-Grace
X-Webkit-CSP
Version
X-Magnolia-Registration
X-Wix-Request-Id
X-RateLimit-Reset
X-Via-JSL
X-EdgeConnect-Cache-Status
Content-Disposition
X-App-Environment
X-Varnish-Grace
X-B-Cache
X-Signature
X-Node-Name
X-Origin-Cache
X-B3-SpanId
X-RemovedCookies
X-Amzn-Remapped-Content-Length
VIX-Pulpo-Upstream-Status
X-ProcessESI
VIX-Pulpo-Node
X-Debug-IsPreview
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Datadog-Sampled
X-Rule
X-Yottaa-Metrics
X-Tumblr-User
X-Debug-IsConnected
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Backend-Name
X-Amz-Replication-Status
X-UUID
SD-X-WS
X-Hl-Ver
X-G
X-RTag
X-Adobe-Loc
MS-CV
X-Device-Type
X-Storage
GEO-INFO
X-Adobe-Content
X-Instance
X-Proxy-Cache-Info
ServerID
Ms-Operation-Id
X-Is-Bot
Liferay-Portal
X-Region
X-Cacheable-TTL
NGB
X-User-Agent
SRV
X-Cache-Age
Country
X-FW-Static
X-FW-Type
X-NYM-Debug-Backend
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-FW-Version
X-Rendered-As
X-FW-Server
X-Status
X-IPS-LoggedIn
X-Cache-Hit
X-Environment-Context
X-L-Path
X-Real-IP
X-Source
X-ServerID
X-Rid
Countrycode
X-NWS-UUID-VERIFY
Akamai-GRN
X-Servername
Surrogate-Key
X-Sucuri-Cache
X-Sucuri-ID
From-Origin
X-WP-CF-Super-Cache-Active
OT-Force-Account-Verify
Cross-Origin-Window-Policy
X-VC-Cache
X-UA
X-WebKit-CSP-Report-Only
X-RM-Cache-TTL
Upgrade-Insecure-Requests
Backend
Amp-Access-Control-Allow-Source-Origin
X-INCAP-ABP
Front
X-Framework
X-Air-Pt
Refresh
X-Xrds-Location
X-AB
X-Mode
Frame-Options
X-Cache-Time
X-Air-Source
X-Buckets
X-Air-Trace-Id
Xet-Cookie
X-Air-Hostname
X-Akamai-Request-ID2
X-Content-Powered-By
X-RID
X-HTML-Minification-Powered-By
X-DataDome
Url
X-Edge-Location
X-Handled-By
X-Endurance-Cache-Level
Webserver
Meta-Geo
X-Akamai-Edgescape
Selected-Fe
X-Webstats-RespID
Filters
X-Azure-Ref-OriginShield
X-VC
X-Timing-Wait
X-UPSTREAM-Address
X-JoinUs
X-Origin-CC
X-Rewrite-Enabled
X-Vcache
X-Origin-Date
X-Origin-TTL
X-SaId
Access-Control-Request-Headers
X-Proxy-Build
X-RCS-CacheZone
X-Rn-Rsrv
X-Wormhole-Sdk
X-Fetched-On
X-VCT
WPO-Cache-Message
X-Reqid
TWC-Connection-Speed
TWC-GeoIP-Country
X-R9-Blue-Green-Version
TWC-Device-Class
X-Provided-By
X-Tumblr-Pixel-2
X-Served-From
X-Origin-Hint
Atl-Traceid
X-Logging-Id
X-Cache-Operation
WPO-Cache-Status
X-Cache-Rule
Property-Id
TWC-GeoIP-LatLong
X-Ms-Version
X-Container-Uri
Webcakes-Region
X-No-Session
X-Generation-Time
X-Origin
X-Git-Commit
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-SRV
TWC-Locale-Group
X-Labrador-Cache-Channel
X-Xfnlog-Site
X-Ms-Request-Id
X-PHP-Host
X-Scope-Id
X-Drupal-Cache-Contexts
X-IPLB-Instance
X-ProxyCache-Status
X-Httpd
X-Hosted-By
X-ProxyCache-Key
X-CMSURLCustom
X-IPLB-Request-ID
X-Drupal-Cache-Tags
Cache
X-Shield-Cache-Expires
X-Redis-Cache
X-BYPASS-REASON
Thinkindot-CacheControl-Type
Thinkindot-Control
Thinkindot-CacheControl
TDXMobile
X-Cms-Context
X-Site-Version
X-Web-Node
X-Adobe-Source
X-Accel-Version
ServedBy
Web-Mar-Node
X-Tb
Section-Io-Id
X-Cache-Status-Check
X-Cache-Debug
X-CDN-Forward
X-Locale
Mn-Server-Ip
X-Thinkindot-L3
X-Varnish-Cache-Hits
X-AWS-Id
X-Cdn-Origin
X-Cluster
X-Director
X-Geo-Region
X-Browser-Name
X-Frame-Option
X-Format
X-Forwarded-Host
X-Say-Cacheable
X-Is-Mobile
X-Is-Supported-Browser
X-Upstream-Ct
X-Soup
X-Is-Tablet
X-LJ-Flow-ID
X-Tcp-Rtt
X-Restarts
X-SayCDN-TTL
X-Is-Desktop
X-S
X-Varnish-Age
X-Upstream-Ht
X-Skip-Cache
X-Say-TTL
X-Loop
X-VWS-Id
X-Tncms
X-Lambda-Id
X-ShardId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-GeoCode
X-Storefront-Renderer-Rendered
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Accept-Language
X-ShopId
X-GeoCountry
Apigw-Requestid
Xserver
X-Alternate-Cache-Key
Cache-Hits
X-Cache-Host
X-Varnish-Beresp-Grace
X-Nginx-Cache
X-Detected-As
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-Cloudmap
X-Extlb
X-Worker
X-Generated-By
X-Optimistic-Header
X-Rocket-Nginx-Serving-Static
X-Lagoon
X-Vercel-Id
X-Vercel-Cache
CDN-RequestId
Azure-InstanceId
Azure-Version
Azure-SiteName
Azure-RegionName
Azure-SlotName
X-B3-Traceid
Node
Source
X-Fastly-Request-Id
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-Cache
CDN-RequestPullSuccess
X-WP-CF-Super-Cache-Cookies-Bypass
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
X-Request-URI
CDN-Uid
AMP-Access-Control-Allow-Source-Origin
X-Pass-Why
Fastcgi-Useragent
X-Vcl-Version
Protected
X-Tumblr-Pixel-3
Cross-Origin-Embedder-Policy
X-GEO
LB
X-App-Version
Alternate-Protocol
X-Connection-Hash
Expiry
X-XRDS-Location
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Cache-Server
X-Ratelimit-Reset
X-ECache
DB-Nickname
X-Cache-Expired-At
Onion-Location
X-Jobs
X-TA-CDN-Provider
Sid
X-Server-W
CF-IPCountry
Environment
X-PHP-Backend
Uber-Trace-Id
Priority
X-Api-Version
X-Response-Served-From
X-Original-Request-Id
X-Fastcgi-Cache
X-LSADC-Cache
X-Proxy-Cache-Status
X-MP-GENERATED-AT
X-Cache-Action
HostName
X-TT-LOGID
X-Cluster-Node
X-LiteSpeed-Cache-Control
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
User-Cache-Control
X-Mg-Request-UUID
X-Nf-Request-Id
X-Uri
X-FB-TRIP-ID
WP-Super-Cache
X-Tx-Id
X-Level-Front-Cache
NM-Fastcgi-Cache
X-Jungle-Id
Ngx.Var.Host
X-D
X-Op-Id-All
Meta-Geo-Continent
X-Ig-Origin-Region
DCR-Processing-Time-Ms
Origin
X-ND-Cache
X-Content-Age
X-Node-Id
X-Esi-Check
X-NCache
X-Conf
X-Mvc-Supplant-Cachable
MD5-Digest
Origin-Agent-Cluster
X-NMSegId
Magicmarker
X-Generated-On
X-Ec-Fail
X-GeoIP
X-GeoIP-City
X-Vdms-Path
Gannett-Cam-Experience-Id
Fusion-Component-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Content-Id
Candidate-Md5Url
X-Dispatcher-Server
X-Forwarded-Site
Lang
X-Epic-Correlation-Id
Edge-Cache
X-Developer
DCR-Decision-By
Content-Secure-Policy
X-FC-Vary-Parameters
X-Gzip
X-Device-Os
A
X-Origin-Expires
X-Ec-GeoHdr
Fusion-Content-Source
X-Org
X-ScT
X-Bc-Bl
Vix-Hermes-Req-Id
X-SRCache-Key
Wxu-Next-Hostname
Wxu-Next-Commit
X-Viewer-Country
X-Clientip
X-Request-Start
Surrogated-Key
X-VTEX-Cache-Server
T-Server
X-BCube-Filmed-By
X-Test
X-Thanos
X-DC
X-A-Wwc
X-Vdms-Version
X-Varnish-Hostname
X-Aed
X-A-Dgt
X-A-Dcw
Wxu-Next-Region
X-TIM-N
X-A
X-A-Ccd
X-A-Dam
Sslversion
X-Rojux
X-Powered-By-VTEX-Cache
X-Platform
X-Cache-NE
X-Vtex-Remote-Cache
Rendered-Blocks
Req-ID
X-VTEX-Cache-Time
X-Proto
Server-Host
X-Bl-Debug
X-Bip
X-Cache-Id
X-NGINX-Cache
X-URL
X-Origin-Response-Time
Fastly-SSL
X-Cache-Info
Fastly-Backend-Name
Powered-By
X-AK-Request-ID
DSUID
X-CGP
Esi-Enabled
X-Cache-TTL-Remaining
X-Edge-Server
PFcat
Release
X-Amz-Storage-Class
L5d-Success-Class
X-CUA
X-Backend-Instance
X-Block-Status
X-Debug-Cache-Fetch
Ssr
Mail-Subject
X-Debug-Cache-Store
X-Auth-Group-Type
X-App-Name
HA-Ipaddr
Ha-Gx-Prefs
X-Csrf-Jwt
We-Hiring
Host-ID
X-Cache-Bucket
X-ApacheServer
W
X-Core-Value
X-GeoIP-Region-Code
X-VG-WebCache
X-Loc
X-Region-Sid
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Policy
X-Request-Time
X-HS-Content-Campaign-Id
X-V-Cache
X-Pubstack
X-UA-Device-Type
X-Mvc-Supplant-OutputCached
X-Newrelic-Synthetics
X-PAYTM-SRV-ID
X-Origin-Time
X-PERF
X-Via-Fastly
X-SB
X-Scheme
X-SD-PageType
X-Nyt-Route
X-Zone
Yak-Timeinfo
X-Eu-Site
X-WA-Info
X-Hnp-Log
Cdnsip
X-Gdpr
Cdncip
Cdn-Request-Time
Cdn-Host
X-From
X-Fmm-Version
X-Varnishpool
Content-Style-Type
Content-Script-Type
X-Fastly-Cache
X-Var-Ttl
X-Gen-Mode
X-Varnish-Director
X-VarnishDD-TTL
AKAMAI
X-Render-Time
X-HN
X-Service
X-GeoIP-Country-Code
X-Geo-Header
Cache-Tv-Group
Canary
X-Req
Cache-Provider
X-Tt-Logid
X-BBC-Edge-Cache-Status
X-VG-TLSProxy
X-SVT-ORM-VERSION
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Authentication
X-Aicache-OS
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Auto-Login
X-Section
X-Server-IP
X-B3-Trace-ID
XM
X-Ad-Load-Variation
X-Human
X-Location
X-Men
X-Micro-Cache
X-Varnish-Beresp-Status
X-Ig-Push-State
X-Ec-Custom-Error
X-Fastly-Backend
X-DPWN-IS-SECURE
X-GoCache-CacheStatus
X-Hash
X-Mly-Id
X-Nginx-Cache-Key
X-Pool
X-We-Are-Hiring
X-Cache-Backend
X-Cache-Aspx
X-Proxied-Request
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Contensis-Viewer-Groups
Gh-Request-Id
X-Cdn-Srv
X-CacheTTL
X-Request-Host
Tube-Return
Machine
On-Server
L
Is-Eu
Fastly-GeoIP-CountryCode
Origin-CC
Origin-EX
Redirect-Candidate
Req-Svc-Chain
Producers
Pramga
Platform
Country-Code
Cluster
Apple-News-Services-Handled
Apple-News-Services-Host
X-Varnish-Beresp-Ttl
X-Acquia-Purge-Cdn-Unconfigured
X-Dc
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Click-Count-Action-Start
Click-Count-Error
CDCHOST
Cache-Key
C-Via
RNT-Machine
Adler-Geo
Web-Mar-Region
Tube-Got-Results
Server-Ext
V-Age
Server-Hostname
Sever-Int
X-Access
RNT-Time
Tube-Get-Contents
True-Client-Country-4JS
Tube-Got-Eval
X-AIR-PT
NGX
Odigeo-Trace-Id
X-Date
X-Slack-Shared-Secret-Outcome
Proxy-Firewall
X-Accel-Expires-Debug
Cdn-Requestid
X-Slack-Backend
X-Up
Datacenter
X-Cs
X-Custom-Header
Debug
X-NodeID
X-COUNTRY
X-LB-ID
X-Ismobilevalue
X-Varnish-Hits
X-Akamai-Transformed
X-Refresh
Locid
X-ID
X-CACHE-GROUP
X-Nananana
X-Pad
X-Varnish-CookieHashed-On
X-LiteSpeed-Tag
X-Amz-Meta-Cb-Modifiedtime
X-Client-Ip
X-Varnish-Remaining-TTL
X-Platform-Router
X-Varnish-CookieINHashed-On
X-Platform-Processor
X-DefElseHash
X-DefHash
X-Platform-Cluster
Mime-Version
Fastly-Drupal-HTML
SID
X-Depends
X-M-Reqid
X-Via-Poph
X-HA-Backend
X-VHOST
CloudFront-Viewer-Country
Pics-Label
X-M-Log
X-Via-Popv
X-Via-Popn
X-Cached-By
X-VC-TTL
X-Servedbyhost
X-Old-Content-Length
X-Datadome
Ngx-Var-Key
GeoIP-Latitude
X-Cache-FS-Status
X-Parent-Response-Time
X-Moov-T
Fastly-Drupal-Html
X-Moov-Xdn-Version
X-CACHE-AGE
X-B3-Parentspanid
X-TH-Server
X-CDN-Cache-Status
X-LB-NoCache
Cross-Origin-Embedder-Policy-Report-Only
X-DynaTrace-JS-Agent
X-TIME
Resin-Trace
GeoIp-Country-Code
Cf-Ipcountry
X-CS
NtCoent-Length
Server-ID
Server-Info
X-Presslabs-Stats
Cdn
X-S-Cookie
X-VCache
X-User
Uri
X-External-Request-Id
X-B-Cookie
X-Application
Cf-Device-Type
BehaviorPad-Version
X-Vgn-Hpd-Reason
X-Nc
X-Wa
X-Destination
X-Litespeed-Tag
X-ZONE
X-APP
X-NewRelic-App-Data
True-Client-IP
FSS-Cache
X-Zen-Fury
X-Aspnet-Duration-Ms
X-Flags
X-Is-Crawler
X-Varnish-Beresp-TTL
X-Providence-Cookie
CDN
X-Route-Name
X-Cache-Date
X-Sigma-Backend
X-Instance-Name
X-Rocket-Build-Number
X-Esi
X-Sigma
X-IAuth-Set-Uid
X-Fpc
X-TX-ID
X-HostName
X-VServer
True-Client-Ip
X-DynaTrace
X-API-Version
Srv
X-Srv
X-Vc
Tcn
X-Segment-20210421
X-Dynatrace-Js-Agent
X-Content-Length
Load-Balancing
X-Branch-Name
X-HITS
X-Page-View
X-Oracle-DMS-ECID
X-Cdn-Forward
X-WA
X-FPC
GeoIP-Country-Code
Serverhost
X-HOST
S-Rt
X-NC
Request-ID
X-APP-VERSION
Ohc-File-Size
X-CLOUD-TRACE-CONTEXT
X-DataCenter
X-Dispatch
Hostname
X-Cdn-Cache-Status
X-Dispatcher-Number
Vc-Max-Age
Type
X-RequestId
Server-Id
Product
X-Sql-Duration-Ms
X-Sql-Count
X-Http-Reason
X-B3-Spanid
X-FL-QIT-DEBUG
X-Lb-Nocache
Geoip-Latitude
X-Irp-Debug
Srvid
X-Webkit-Csp-Report-Only
Cl-Cache
X-Geo
WZWS-RAY
X-CSRF-TOKEN
X-ServedByHost
Edge-Copy-Time
X-Via-SSL
IsBot
X-Bug-Bounty
Cloudfront-Viewer-Country
X-Ckpd-Fst-Backend
X-Via-Edge
X-Via-CDN
X-Owner
DataCenter
ServerName
X-SIPLIST1
X-VCL-Version
XkeyRZ
X-Core-Mission
PICS-Label
Cross-Origin-Opener-Policy-Report-Only
Ohc-Cache-HIT
MIME-Version
CacheControlHeader
Epwk-X-Cache
X-Proxy-CacheRZ
Origin-Trial
Lb
X-Cache-Ttl
X-Hit
X-Qloud-Router
CountryCode
X-Ha-Backend
X-Correlation-ID
X-Via-PopV
X-Via-PopN
X-App
N-Cache
ServerHost
X-Ua
X-Via-PopH
Rtss
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-MiniProfiler-Ids
X-Amz-Meta-Opti
X-Lb-Id
X-MSEdge-Features
X-MSEdge-Flight
X-Fastly-Country-Code
X-Sqd-Stime
X-Sqd-Ctime
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Datacenter
X-Web-Server
Warning
X-Service-Response-Time
X-Acquia-Site
Sm-Log-Id
X-LAGOON
X-Amz-Meta-S3b-Last-Modified
Akamai-Cache-Status
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-IN-APIGATEWAYSSL
X-Akamai-Device-Characteristics
X-Limited
X-Vmg-Version
User-Agent
Cneonction
X-IN-APIGATEWAY
Expect-Staple
X-Dw-Trace-Id
X-CF-Lambda-Fn
X-Check-Cacheable
X-Serial
X-Th-Server
X-Proxy-Cache-La3
Xkey-La3
Xkeylog
X-Akamai-Pragma-Client-IP
X-RAMCache
X-Ramcache
X-Snapshot-Date
X-CF-Lambda-Version
X-Requestid
X-Cdn-Request-ID
X-Forwarded-Path
X-Orig-Expires
X-Tenant
Ngx
X-Shop-Environment
X-Cache-Type