Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Request-ID
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
CF-Ray
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
Permissions-Policy
X-Age
X-Vhost
X-Amz-Version-Id
Allow
X-Dispatcher
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-WebKit-CSP
X-Server-Id
X-Host
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Litespeed-Cache
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Content-Location
X-Application-Context
X-Node
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-CST
X-NWS-LOG-UUID
X-Country
Service-Worker-Allowed
X-Country-Code
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Url
Rating
X-Rack-Cache
X-Oneagent-Js-Injection
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Times
X-Server-Name
X-FTR-Request-ID
X-Vname
X-PC
X-TtlSet
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Webkit-Csp
X-Browser-Type
X-Powered-By-Plesk
X-ESI
X-Cnection
X-ECACHE
X-Upstream
X-MS-InvokeApp
X-GitHub-Request-Id
Edge-Control
X-Element-Page-Cache
X-Ac
Verso
X-GoogleNews-Bot
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-D2id
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
X-Aws-Lambda-Call-Status
X-Ser
X-Vcap-Request-Id
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Abt-Application-Version
X-B3-TraceId
X-Mod-Pagespeed
X-Navigation-Version
AR-CACHE
SPIisLatency
SPRequestDuration
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Cache-TTL
SPRequestGuid
X-SharePointHealthScore
X-Ruxit-Js-Agent
Fastly-Restarts
X-Amz-Rid
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Display
X-Sol
Pagespeed
X-Middleton-Display
X-Client-IP
Edge-Cache-Tag
X-Mg-S
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Powered-CMS
X-Middleton-Response
X-Amzn-Trace-Id
Response
Cache-Status
X-Cache-Key
Access-Control-Request-Method
X-Version
X-Goog-Hash
X-VARITI-CCR
X-RateLimit-Remaining
X-Fastly-Request-ID
X-ARC
RTSS
X-Content-Digest
X-TraceId
X-Forwarded-For
Cross-Origin-Resource-Policy
X-Recruiting
X-T
Realpath
X-Correlation-Id
X-MSEdge-Ref
X-Ratelimit-Limit
X-Ttl
X-Varnish-TTL
Front-End-Https
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
MS-Author-Via
X-Cached
Fastcgi-Cache
Content-MD5
X-Ua-Browser
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-PDP-UNCACHING-HASH
X-Country-Code-Real
Payment
Server-Node
X-FTR-Balancer
X-FTR-Backend
X-Protected-By
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Request-Processing-Time
X-Request-Received
X-Shield-Request-Id
MicrosoftSharePointTeamServices
X-Forwarded-Proto
Public-Key-Pins
Arr-Disable-Session-Affinity
X-HS-Combine-CSS
TP-Cache
X-Frontend
X-SRCache-Fetch-Status
X-LLID
X-SRCache-Store-Status
X-Distributor
X-FTR-Expires
X-Accel-Expires
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ratelimit-Remaining
X-Origin-Cache-Key
Count-Hit
X-Server-ID
X-GUploader-UploadID
X-Origin-Server
X-LB-Cache
X-ORACLE-DMS-RID
X-NODE
X-Hits
X-Ezoic-Cdn
X-TTL
X-Microsite
X-Request-Handler-Origin-Region
X-Content-Security-Policy-Report-Only
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-PressLabs-Stats
X-AppVersion
X-Az
X-Activity-Id
Host
X-Www-Served-By
MRF-Tech
X-B3-TraceId-Primal
X-Cluster-Name
Mrf-Cache-Status
X-Varnish-Server
X-Varnish-Backend
Cache-Tags
X-App-Server
Retry-After
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
X-Ua-Device
Server-Name
X-Hostname
X-Geo-Country
Cleartype
X-NGENIX-Cache
X-Envoy-Decorator-Operation
X-Newrelic-App-Data
Referer-Policy
X-Goog-Metageneration
X-DIS-Request-ID
X-Upgrade-Enabled
TP-L2-Cache
X-Id
X-Seen-By
X-CSRF-Token
X-Git-Hash
Access-Control-Allow-Method
X-Azure-Ref
X-ORACLE-DMS-ECID
TCN
X-F-Cache
X-CCDN-Origin-Time
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Hcs-Proxy-Type
X-Load-Cache
X-CCDN-CacheTTL
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Unique-Id
Filterid
X-Oracle-Dms-Ecid
X-Proxy
X-RateLimit-Limit
Healthy
X-Grace
X-Revision
Paypal-Debug-Id
X-Debug-Info
Section-Io-Cache
X-Cache-Control
X-Px
X-Request-Guid
X-Trace-Id
DC
X-TT
X-B
X-B3-Sampled
X-FB-Debug
X-Type
X-Contextid
X-Fb-Rlafr
X-Page-Id
X-Logged-In
X-Varnish-Ttl
X-N
X-Mobile
X-Oracle-Dms-Rid
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Viewport
X-Debug
X-Whom
X-Language
X-Goog-Stored-Content-Length
Charset
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
Fastly-SWR
Fastly-SIE
X-XRDS-LOCATION
X-Template
X-Cache-Grace
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Content-Options
X-Datadog-Parent-Id
Version
Content-Disposition
X-EdgeConnect-Cache-Status
X-Time
X-Via-JSL
X-Wix-Request-Id
X-Magnolia-Registration
X-App-Environment
X-Webkit-CSP
X-Varnish-Grace
X-B-Cache
X-Signature
X-Node-Name
X-Rid
X-RateLimit-Reset
X-B3-SpanId
X-Origin-Cache
VIX-Pulpo-Node
X-RemovedCookies
VIX-Pulpo-Upstream-Status
X-ProcessESI
SRV
X-Rule
X-Tumblr-User
X-Tumblr-Pixel-1
X-Debug-IsPreview
X-Tumblr-Pixel-0
X-Debug-IsConnected
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Yottaa-Metrics
X-Backend-Name
X-G
SD-X-WS
X-Amz-Replication-Status
X-Amzn-Remapped-Content-Length
X-Datadog-Sampled
GEO-INFO
Ms-Operation-Id
MS-CV
ServerID
X-Adobe-Loc
X-Adobe-Content
X-Device-Type
X-Storage
X-FW-Version
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Serve
X-Hl-Ver
X-RTag
X-FW-Hash
X-Proxy-Cache-Info
X-Instance
X-FW-Dynamic
X-Is-Bot
X-Rendered-As
NGB
X-UUID
X-Cacheable-TTL
X-NYM-Debug-Backend
Country
Liferay-Portal
X-L-Path
X-Cache-Hit
X-User-Agent
X-IPS-LoggedIn
X-Status
X-Environment-Context
X-Region
X-NWS-UUID-VERIFY
X-Real-IP
X-Cache-Age
X-Source
X-ServerID
Countrycode
Surrogate-Key
Amp-Access-Control-Allow-Source-Origin
Akamai-GRN
X-Servername
X-WP-CF-Super-Cache-Active
X-Sucuri-Cache
Cross-Origin-Window-Policy
X-Sucuri-ID
OT-Force-Account-Verify
X-VC-Cache
From-Origin
X-UA
X-Xrds-Location
X-RM-Cache-TTL
Upgrade-Insecure-Requests
Backend
X-WebKit-CSP-Report-Only
X-Framework
Front
X-Air-Pt
X-INCAP-ABP
X-Mode
Refresh
X-AB
X-Air-Hostname
X-Cache-Time
Frame-Options
X-Air-Source
X-Air-Trace-Id
X-DataDome
X-Content-Powered-By
Xet-Cookie
X-Akamai-Request-ID2
X-HTML-Minification-Powered-By
X-URL
X-Nginx-Cache
X-Buckets
X-Handled-By
X-Wormhole-Sdk
Url
X-Edge-Location
X-Vcache
Webserver
Selected-Fe
X-No-Session
X-Xfnlog-Site
X-Timing-Wait
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-JoinUs
X-Cluster
X-Webstats-RespID
Filters
X-SRV
Meta-Geo
X-Origin-Date
Access-Control-Request-Headers
X-Reqid
X-RCS-CacheZone
X-SaId
X-Rn-Rsrv
X-Rewrite-Enabled
X-Proxy-Build
TWC-GeoIP-LatLong
X-LJ-Flow-ID
X-VCT
X-Logging-Id
X-Akamai-Edgescape
X-Origin-CC
X-Tumblr-Pixel-2
Webcakes-App-Version
X-Container-Uri
X-Drupal-Cache-Tags
X-IPLB-Instance
X-Cache-Rule
X-PHP-Host
X-AWS-Id
X-IPLB-Request-ID
X-Cache-Operation
X-R9-Blue-Green-Version
X-Origin-Hint
X-VWS-Id
X-Azure-Ref-OriginShield
WPO-Cache-Message
WPO-Cache-Status
X-Labrador-Cache-Channel
X-Origin-TTL
X-Origin
Webcakes-Region
Atl-Traceid
TWC-Privacy
Webcakes-App-Name
X-Provided-By
ServedBy
TWC-Connection-Speed
Property-Id
X-Git-Commit
X-Served-From
TWC-Device-Class
TWC-GeoIP-Country
TWC-Locale-Group
X-Fetched-On
X-Redis-Cache
X-Generation-Time
X-Httpd
X-Cache-Debug
X-Hosted-By
X-ProxyCache-Status
X-Site-Version
X-ProxyCache-Key
X-Ms-Version
Web-Mar-Node
X-BYPASS-REASON
X-Cache-Status-Check
X-Adobe-Source
X-Routing-Service
X-CDN-Forward
Mn-Server-Ip
X-Cloudmap
X-Tb
X-Cms-Context
X-Zipkin-Id
X-Locale
X-VC
X-Proxied
X-Restarts
X-Web-Node
X-Drupal-Cache-Contexts
X-Varnish-Cache-Hits
X-Ms-Request-Id
Section-Io-Id
X-Extlb
X-Geo-Region
X-Director
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
TDXMobile
X-Cdn-Origin
X-Forwarded-Host
X-Format
X-CMSURLCustom
X-Frame-Option
X-Lambda-Id
X-Browser-Name
X-Skip-Cache
X-Loop
X-Tcp-Rtt
X-Thinkindot-L3
X-Shield-Cache-Expires
X-Scope-Id
X-S
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Tncms
X-Soup
X-Is-Tablet
X-Is-Desktop
X-Is-Mobile
X-Is-Supported-Browser
Cache
Apigw-Requestid
Accept-Language
X-Accel-Version
X-Varnish-Age
X-Upstream-Ht
X-Upstream-Ct
X-ShopId
X-GeoCode
X-Shopify-Stage
X-ShardId
Cache-Hits
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-GeoCountry
X-Storefront-Renderer-Rendered
Xserver
X-Cache-Host
X-Alternate-Cache-Key
X-Detected-As
X-Varnish-Beresp-Grace
X-Generated-By
X-Lagoon
X-RID
X-Optimistic-Header
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Rocket-Nginx-Serving-Static
X-Worker
X-Vercel-Cache
X-Vercel-Id
Source
Azure-SlotName
Azure-SiteName
Azure-RegionName
X-XRDS-Location
Azure-Version
Azure-InstanceId
Node
LB
X-Request-URI
X-WP-CF-Super-Cache-Cookies-Bypass
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
CDN-CachedAt
Protected
X-Fastcgi-Cache
CDN-RequestPullCode
X-B3-Traceid
CDN-Cache
CDN-Uid
CDN-RequestPullSuccess
Fastcgi-Useragent
X-App-Version
X-Vcl-Version
X-Pass-Why
Cross-Origin-Embedder-Policy
CDN-RequestId
X-Connection-Hash
Expiry
X-Tumblr-Pixel-3
X-GEO
X-Ratelimit-Reset
Alternate-Protocol
Onion-Location
X-Cache-Expired-At
X-Cache-Server
X-Tec-Api-Root
X-Jobs
X-Tec-Api-Version
DB-Nickname
X-Tec-Api-Origin
Priority
X-Server-W
X-TA-CDN-Provider
AMP-Access-Control-Allow-Source-Origin
CF-IPCountry
X-PHP-Backend
Environment
Uber-Trace-Id
X-DC
X-Proxy-Cache-Status
X-Fastly-Request-Id
X-Cluster-Node
X-Cache-Action
X-LSADC-Cache
Locale
X-Api-Version
X-Urbn-Site-Id
X-Urbn-Context-Path
User-Cache-Control
X-ID
X-Uri
X-MP-GENERATED-AT
X-Response-Served-From
X-Original-Request-Id
X-Mg-Request-UUID
Sid
X-Tx-Id
HostName
X-FB-TRIP-ID
X-TT-LOGID
X-FC-Vary-Parameters
Sslversion
X-Gen-Mode
X-GeoIP-City
X-Forwarded-Site
Surrogated-Key
X-NCache
T-Server
Vix-Hermes-Req-Id
X-Esi-Check
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Varnish-Beresp-Ttl
X-A
X-ScT
Wxu-Next-Commit
X-ND-Cache
Wxu-Next-Hostname
X-Rojux
Wxu-Next-Region
X-Vtex-Remote-Cache
X-Request-Start
Rendered-Blocks
X-Origin-Expires
Edge-Cache
DCR-Processing-Time-Ms
DCR-Decision-By
Magicmarker
Lang
X-Platform
Gannett-Cam-Experience-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Content-Secure-Policy
MD5-Digest
Candidate-Md5Url
Origin-Agent-Cluster
Cache-Tv-Group
X-A-Wwc
Req-ID
Origin
X-Node-Id
X-Org
Meta-Geo-Continent
X-Op-Id-All
X-Powered-By-VTEX-Cache
Ngx.Var.Host
A
X-SB
X-TIM-N
X-Jungle-Id
X-UA-Device-Type
X-Bc-Bl
X-Gzip
X-Ig-Origin-Region
X-Device-Os
Fusion-Deployment-Id
X-Developer
X-BCube-Filmed-By
X-Bip
X-Block-Status
X-D
X-Cache-Id
X-Varnish-Hostname
X-Cache-NE
X-Vdms-Path
X-Bl-Debug
X-Aed
X-Vdms-Version
X-Hnp-Log
X-Thanos
X-Ec-GeoHdr
X-Clientip
X-Tt-Logid
X-VTEX-Cache-Server
Cdn-Requestid
X-Content-Age
X-VTEX-Cache-Time
X-LiteSpeed-Cache-Control
X-Ec-Fail
X-Conf
X-SRCache-Key
X-Epic-Correlation-Id
X-Dispatcher-Server
X-Mvc-Supplant-Cachable
X-Origin-Response-Time
WP-Super-Cache
X-Cache-Bucket
NM-Fastcgi-Cache
X-HN
X-Cache-Info
L5d-Success-Class
Origin-CC
X-Cdn-Srv
X-HS-Content-Campaign-Id
X-Cache-TTL-Remaining
Mail-Subject
X-CUA
X-PAYTM-SRV-ID
Ha-Gx-Prefs
HA-Ipaddr
X-CGP
X-Csrf-Jwt
Server-Hostname
X-Eu-Site
We-Hiring
W
X-Fastly-Cache
X-Mvc-Supplant-OutputCached
X-GeoIP-Region-Code
X-Edge-Server
X-Loc
X-Amz-Storage-Class
X-AK-Request-ID
X-ApacheServer
X-App-Name
X-Auto-Login
X-Auth-Group-Type
X-Backend-Instance
X-Fmm-Version
X-NMSegId
X-Nginx-Cache-Key
X-Level-Front-Cache
Release
PFcat
Powered-By
Server-Ext
Server-Host
Ssr
X-GeoIP-Country-Code
X-Generated-On
X-Geo-Header
Sever-Int
Origin-EX
X-Proto
X-VarnishDD-TTL
X-Varnishpool
AKAMAI
X-Varnish-Director
X-RateLimit-Limit-Second
X-VG-WebCache
X-Via-Fastly
Canary
CDCHOST
Cache-Provider
X-WA-Info
X-Viewer-Country
X-RateLimit-Remaining-Second
X-Service
X-Request-Time
X-Client-Ip
X-Scheme
X-SD-PageType
Fastly-SSL
X-Test
X-V-Cache
X-Region-Sid
X-Render-Time
X-Var-Ttl
X-Req
Cdn-Host
C-Via
X-Policy
X-PERF
Content-Style-Type
Content-Script-Type
Yak-Timeinfo
XM
Fastly-Backend-Name
Cdn-Request-Time
Cdncip
DSUID
Cdnsip
X-Pubstack
X-GeoIP
X-Location
X-Fastly-Backend
X-Tb-Optimization-Total-Bytes-Saved
X-B3-Trace-ID
X-Men
X-Micro-Cache
X-Sn-Servicetimems
X-Aicache-OS
X-Ad-Load-Variation
X-Gdpr
X-ECache
X-Mly-Id
X-From
X-BBC-Edge-Cache-Status
X-SVT-ORM-RULES
X-Zone
X-SVT-ORM-VERSION
X-DPWN-IS-SECURE
X-Debug-Cache-Fetch
X-Human
X-Access
X-CacheTTL
X-Wikidot-Static-Cache
X-Contensis-Viewer-Groups
X-Wikidot-Backend
X-Core-Value
X-We-Are-Hiring
X-Debug-Cache-Store
X-VG-TLSProxy
X-Ec-Custom-Error
X-Varnish-Beresp-Status
X-Ig-Push-State
X-Varnish-Authentication
Gh-Request-Id
X-Ismobilevalue
X-Cache-Backend
X-Cache-Aspx
X-GoCache-CacheStatus
X-Acquia-Purge-Cdn-Unconfigured
Req-Svc-Chain
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Redirect-Candidate
Apple-News-Services-Host
RNT-Machine
X-Proxied-Request
Click-Count-Action-Start
RNT-Time
L
X-Pool
Country-Code
Cluster
On-Server
X-Nyt-Route
Click-Count-Error
Platform
Cache-Key
Machine
Producers
Pramga
Adler-Geo
Apple-News-Services-Handled
Is-Eu
Host-ID
V-Age
Web-Mar-Region
X-Section
Fastly-GeoIP-CountryCode
X-Server-IP
X-Origin-Time
X-Request-Host
Esi-Enabled
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
True-Client-Country-4JS
Tube-Return
X-Newrelic-Synthetics
X-Slack-Backend
X-Up
X-Hash
X-Slack-Shared-Secret-Outcome
X-Accel-Expires-Debug
NGX
Proxy-Firewall
Odigeo-Trace-Id
X-Date
SID
Datacenter
X-AIR-PT
X-Custom-Header
X-NodeID
Debug
X-NGINX-Cache
X-Varnish-Hits
X-LB-ID
X-Cs
Fastly-Drupal-HTML
X-COUNTRY
X-Nananana
X-Dc
X-Pad
X-Varnish-CookieINHashed-On
X-CACHE-GROUP
X-Varnish-CookieHashed-On
X-DefHash
X-DefElseHash
X-Varnish-Remaining-TTL
X-Refresh
Pics-Label
CloudFront-Viewer-Country
X-Via-Popv
X-Via-Popn
X-HA-Backend
X-Via-Poph
Locid
X-Nf-Request-Id
Mime-Version
X-Depends
X-Servedbyhost
X-Amz-Meta-Cb-Modifiedtime
X-Platform-Cluster
X-Akamai-Transformed
X-Platform-Router
X-Platform-Processor
X-VHOST
GeoIP-Latitude
X-VC-TTL
X-CACHE-AGE
X-TIME
X-LiteSpeed-Tag
Ngx-Var-Key
X-Cache-FS-Status
X-Parent-Response-Time
X-Datadome
X-LB-NoCache
X-M-Log
X-Old-Content-Length
X-M-Reqid
X-Cached-By
X-B3-Parentspanid
X-Moov-T
X-TH-Server
X-Moov-Xdn-Version
X-CS
Server-ID
Cross-Origin-Embedder-Policy-Report-Only
X-Litespeed-Tag
Cdn
Resin-Trace
X-Wa
Server-Info
X-CDN-Cache-Status
X-Nc
Cf-Ipcountry
X-DynaTrace-JS-Agent
Fastly-Drupal-Html
BehaviorPad-Version
NtCoent-Length
GeoIp-Country-Code
X-ZONE
X-Presslabs-Stats
Cf-Device-Type
X-External-Request-Id
X-Destination
X-S-Cookie
X-Vgn-Hpd-Reason
X-VCache
X-Application
X-User
X-HITS
X-Fpc
X-IAuth-Set-Uid
X-APP
X-B-Cookie
Uri
X-NewRelic-App-Data
X-Zen-Fury
X-Vc
FSS-Cache
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Route-Name
X-Flags
X-Is-Crawler
True-Client-IP
X-Instance-Name
X-Cache-Date
X-Sigma
X-API-Version
X-Sigma-Backend
True-Client-Ip
X-Esi
X-Rocket-Build-Number
X-Content-Length
X-HostName
X-TX-ID
CDN
X-DynaTrace
X-VServer
Serverhost
X-Srv
X-Dynatrace-Js-Agent
X-Varnish-Beresp-TTL
GeoIP-Country-Code
Load-Balancing
X-Branch-Name
Tcn
S-Rt
X-Segment-20210421
X-Page-View
X-Oracle-DMS-ECID
X-Dispatcher-Number
X-Cdn-Cache-Status
Hostname
Srv
X-HOST
Request-ID
X-Cdn-Forward
X-Cache-Ttl
Ohc-File-Size
X-RequestId
X-NC
Vc-Max-Age
X-WA
X-FPC
X-Dispatch
Product
X-DataCenter
X-Webkit-Csp-Report-Only
Type
ServerName
X-Sql-Duration-Ms
X-Http-Reason
X-APP-VERSION
X-Sql-Count
X-B3-Spanid
Server-Id
X-Irp-Debug
Srvid
X-FL-QIT-DEBUG
Geoip-Latitude
X-Bug-Bounty
X-Ckpd-Fst-Backend
X-Geo
Cl-Cache
X-Lb-Nocache
CacheControlHeader
X-ServedByHost
IsBot
X-Owner
Edge-Copy-Time
WZWS-RAY
X-Via-SSL
X-SIPLIST1
X-Via-CDN
X-CSRF-TOKEN
DataCenter
X-Via-Edge
X-VCL-Version
Epwk-X-Cache
Cloudfront-Viewer-Country
MIME-Version
XkeyRZ
Ohc-Cache-HIT
X-CACHE-KEY
Cross-Origin-Opener-Policy-Report-Only
X-Core-Mission
Origin-Trial
X-Proxy-CacheRZ
X-Hit
CountryCode
X-App
X-Ua
N-Cache
X-Correlation-ID
PICS-Label
X-Via-PopV
X-Via-PopH
X-Ha-Backend
X-Qloud-Router
X-Via-PopN
Rtss
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-MSEdge-Features
X-MSEdge-Flight
X-MiniProfiler-Ids
ServerHost
X-Amz-Meta-Opti
X-Fastly-Country-Code
X-Lb-Id
Lb
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Service-Response-Time
Sm-Log-Id
X-Limited
Warning
X-Vmg-Version
X-Web-Server
User-Agent
X-Datacenter
Cneonction
X-Sqd-Ctime
X-Akamai-Device-Characteristics
X-Sqd-Stime
X-LAGOON
X-Litespeed-Cache-Control
X-Gamma-Serve
X-Amz-Meta-S3b-Last-Modified
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-Udemy-Cache-App-Namespace
X-Amz-Meta-Sha256
X-IN-APIGATEWAYSSL
Akamai-Cache-Status
X-Cdn-Request-ID
X-Cache-Type
X-Akamai-Pragma-Client-IP
X-RAMCache
X-Proxy-Cache-La3
Xkeylog
X-Requestid
Expect-Staple
X-Orig-Expires
X-Shop-Environment
Xkey-La3
X-Check-Cacheable
X-CF-Lambda-Fn
Ngx
X-CF-Lambda-Version
X-Snapshot-Date
X-Ramcache
X-Tenant
X-Serial
X-Th-Server
X-Forwarded-Path