Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Xss-Protection
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Request-ID
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
Permissions-Policy
X-Ws-Request-Id
Xkey
X-Rq
X-Age
X-Vhost
X-Amz-Version-Id
X-Dispatcher
Allow
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-WebKit-CSP
X-Host
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Content-Location
X-Node
X-Application-Context
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
P3p
X-NWS-LOG-UUID
X-Country
X-CST
Service-Worker-Allowed
X-Country-Code
X-Litespeed-Cache
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
Rating
X-Rack-Cache
X-Url
X-Amz-Server-Side-Encryption
X-Times
Nginx-Cache
X-FTR-Request-ID
X-Vname
X-TtlSet
X-PC
X-Server-Name
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Oneagent-Js-Injection
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Webkit-Csp
X-Powered-By-Plesk
X-ESI
X-Cnection
X-ECACHE
X-GitHub-Request-Id
X-Upstream
Edge-Control
X-D2id
X-MS-InvokeApp
X-Element-Page-Cache
Verso
X-Ac
AR-PoweredBy
AR-Request-ID
AR-SID
AR-ATIME
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Exp-Id
X-Kinja-Server
X-Cdn-Fetch
X-FastCGI-Cache
X-Ser
X-Vcap-Request-Id
Accept-Ch-Lifetime
X-Cache-TTL
X-Abt-Application-Version
X-B3-TraceId
X-Navigation-Version
AR-CACHE
X-NF-Request-ID
X-Mod-Pagespeed
X-Dw-Request-Base-Id
SPIisLatency
SPRequestDuration
X-Aws-Lambda-Call-Status
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
Fastly-Restarts
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Middleton-Display
X-Sol
Display
Pagespeed
Edge-Cache-Tag
X-Mg-S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Ruxit-Js-Agent
X-Client-IP
S
X-Powered-CMS
Response
X-Middleton-Response
Cache-Status
X-Goog-Hash
X-Amzn-Trace-Id
Access-Control-Request-Method
X-Version
X-VARITI-CCR
X-Fastly-Request-ID
X-ARC
RTSS
X-Cache-Key
X-RateLimit-Remaining
X-Content-Digest
X-TraceId
Cross-Origin-Resource-Policy
X-Forwarded-For
X-Recruiting
X-Ratelimit-Limit
X-T
X-Varnish-TTL
Realpath
X-Correlation-Id
X-MSEdge-Ref
Front-End-Https
Fastcgi-Cache
X-Cached
MS-Author-Via
X-PDP-UNCACHING-HASH
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Ratelimit-Remaining
Content-MD5
X-TTL
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Ua-Browser
X-Protected-By
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-Shield-Request-Id
X-FTR-Backend
X-Country-Code-Real
X-Request-Processing-Time
X-Request-Received
Server-Node
Public-Key-Pins
Payment
X-Forwarded-Proto
X-HS-Combine-CSS
TP-Cache
X-LLID
X-Frontend
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Arr-Disable-Session-Affinity
MicrosoftSharePointTeamServices
X-Distributor
X-FTR-Expires
X-Accel-Expires
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-ORACLE-DMS-RID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ttl
Count-Hit
X-GUploader-UploadID
X-Server-ID
X-Origin-Server
X-LB-Cache
X-NODE
X-Ezoic-Cdn
X-Microsite
X-Request-Handler-Origin-Region
X-Origin-Cache-Key
X-Content-Security-Policy-Report-Only
X-AppVersion
X-Az
X-Activity-Id
X-PressLabs-Stats
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Host
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Www-Served-By
X-Cluster-Name
X-Varnish-Server
X-Varnish-Backend
X-App-Server
Retry-After
Cache-Tags
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-Ua-Device
X-Hits
X-Newrelic-App-Data
Cleartype
X-Geo-Country
X-Hostname
X-NGENIX-Cache
X-Envoy-Decorator-Operation
X-Goog-Metageneration
X-ORACLE-DMS-ECID
Referer-Policy
X-CSRF-Token
X-DIS-Request-ID
X-Upgrade-Enabled
TP-L2-Cache
X-Seen-By
Access-Control-Allow-Method
X-Git-Hash
X-Azure-Ref
TCN
X-Unique-Id
Filterid
X-F-Cache
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Load-Cache
X-Proxy
X-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Revision
Healthy
X-Trace-Id
Section-Io-Cache
X-Grace
X-Request-Guid
X-Cache-Control
X-Px
X-B
X-B3-Sampled
DC
X-TT
Paypal-Debug-Id
X-Debug-Info
X-Type
X-Contextid
X-Page-Id
X-Logged-In
X-FB-Debug
X-Fb-Rlafr
X-Mobile
X-N
X-Debug
X-Oracle-Dms-Ecid
Viewport
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-RateLimit-Limit
X-Whom
Fastly-SWR
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
Fastly-SIE
X-Goog-Storage-Class
X-XRDS-LOCATION
X-Varnish-Ttl
X-Datadog-Trace-Id
X-Template
X-Datadog-Parent-Id
X-Oracle-Dms-Rid
X-Datadog-Sampling-Priority
Charset
X-Content-Options
Version
Content-Disposition
X-Via-JSL
X-Cache-Grace
X-Varnish-Grace
X-Magnolia-Registration
X-Webkit-CSP
X-Wix-Request-Id
X-App-Environment
X-EdgeConnect-Cache-Status
X-Language
X-Origin-Cache
X-Signature
X-B-Cache
X-Rid
X-Time
X-B3-SpanId
X-Node-Name
VIX-Pulpo-Upstream-Status
X-RemovedCookies
SRV
X-ProcessESI
VIX-Pulpo-Node
X-Debug-IsPreview
X-Tumblr-User
X-Yottaa-Optimizations
X-Datadog-Sampled
X-Yottaa-Metrics
X-Debug-IsConnected
X-Rule
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Ms-Operation-Id
SD-X-WS
X-Amz-Replication-Status
X-Hl-Ver
X-UUID
X-RTag
X-G
MS-CV
X-Adobe-Loc
X-Storage
X-Adobe-Content
ServerID
X-FW-Hash
GEO-INFO
X-Backend-Name
X-FW-Type
X-FW-Version
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Dynamic
X-Amzn-Remapped-Content-Length
X-Instance
X-Proxy-Cache-Info
X-Is-Bot
X-NYM-Debug-Backend
X-Cacheable-TTL
Liferay-Portal
X-Device-Type
NGB
X-Rendered-As
X-Environment-Context
X-L-Path
X-IPS-LoggedIn
X-Cache-Hit
X-Region
X-User-Agent
X-Status
Country
X-RateLimit-Reset
Surrogate-Key
Countrycode
X-Real-IP
X-Source
X-URL
X-ServerID
X-NWS-UUID-VERIFY
Akamai-GRN
Amp-Access-Control-Allow-Source-Origin
X-Sucuri-Cache
X-WP-CF-Super-Cache-Active
Cross-Origin-Window-Policy
X-Sucuri-ID
X-Servername
OT-Force-Account-Verify
X-Cache-Age
X-UA
X-VC-Cache
From-Origin
X-RM-Cache-TTL
X-WebKit-CSP-Report-Only
Front
X-Framework
X-Air-Pt
Upgrade-Insecure-Requests
Backend
X-INCAP-ABP
Refresh
X-Mode
X-Wormhole-Sdk
X-AB
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Content-Powered-By
X-Cache-Time
X-Akamai-Request-ID2
X-DataDome
X-Xrds-Location
X-Handled-By
Xet-Cookie
X-Nginx-Cache
X-Edge-Location
Frame-Options
X-HTML-Minification-Powered-By
Url
X-Endurance-Cache-Level
X-Timing-Wait
X-Rn-Rsrv
X-Origin-TTL
X-Origin-CC
X-SaId
X-SRV
X-Rewrite-Enabled
Selected-Fe
Filters
X-Proxy-Build
X-UPSTREAM-Address
Meta-Geo
X-RCS-CacheZone
X-Vcache
X-Xfnlog-Site
X-CDN-Forward
X-Webstats-RespID
X-JoinUs
X-Origin
X-Served-From
ServedBy
X-AWS-Id
X-No-Session
WPO-Cache-Status
Webcakes-App-Name
X-Cache-Rule
X-Cache-Operation
X-Origin-Hint
Accept-Language
X-Origin-Date
X-Container-Uri
X-Logging-Id
TWC-Locale-Group
TWC-Device-Class
X-Drupal-Cache-Tags
Webserver
WPO-Cache-Message
X-LJ-Flow-ID
Property-Id
X-Tumblr-Pixel-2
Cache
X-Akamai-Edgescape
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Connection-Speed
X-VWS-Id
Atl-Traceid
X-Provided-By
X-Reqid
X-Labrador-Cache-Channel
X-Git-Commit
X-PHP-Host
TWC-GeoIP-Country
X-XRDS-Location
X-Cluster
Access-Control-Request-Headers
Webcakes-App-Version
Webcakes-Region
X-IPLB-Request-ID
X-Restarts
X-Cloudmap
Mn-Server-Ip
X-Tb
Cache-Hits
X-Redis-Cache
Web-Mar-Node
X-Azure-Ref-OriginShield
X-Cache-Debug
X-Cms-Context
X-VCT
X-Zipkin-Id
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Adobe-Source
X-Site-Version
Section-Io-Id
X-Accel-Version
Thinkindot-Control
X-Proxied
X-Thinkindot-L3
X-Buckets
X-Hosted-By
X-Routing-Service
X-R9-Blue-Green-Version
X-Fetched-On
X-Extlb
X-Locale
X-Drupal-Cache-Contexts
X-Shield-Cache-Expires
X-Varnish-Cache-Hits
X-IPLB-Instance
X-Scope-Id
TDXMobile
X-Web-Node
X-CMSURLCustom
X-Is-Supported-Browser
X-ProxyCache-Status
X-Tncms
X-ProxyCache-Key
X-Skip-Cache
X-Soup
X-Tcp-Rtt
X-Upstream-Ct
X-Upstream-Ht
X-Say-Cacheable
X-S
X-Say-TTL
X-SayCDN-TTL
X-Varnish-Age
X-Ms-Version
X-Ms-Request-Id
X-Frame-Option
X-Generation-Time
X-Forwarded-Host
X-Format
X-BYPASS-REASON
X-Director
X-Geo-Region
X-Httpd
X-Lambda-Id
X-Loop
X-Is-Tablet
X-Is-Mobile
X-Is-Desktop
X-Browser-Name
Apigw-Requestid
X-Cache-Status-Check
Xserver
X-GeoCode
X-Detected-As
X-Cache-Host
X-Varnish-Beresp-Grace
X-ShardId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-ShopId
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-GeoCountry
X-Generated-By
X-Cdn-Origin
X-VC
X-Optimistic-Header
X-RID
X-TA-CDN-Provider
X-Lagoon
X-Rocket-Nginx-Serving-Static
X-Ratelimit-Reset
X-Worker
LB
Source
X-Vercel-Id
X-Vercel-Cache
Azure-SlotName
Azure-RegionName
X-Request-URI
Azure-InstanceId
Azure-Version
Azure-SiteName
X-WP-CF-Super-Cache-Cookies-Bypass
Node
X-B3-Traceid
Protected
Fastcgi-Useragent
CDN-Uid
X-Pass-Why
CDN-Cache
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
X-Vcl-Version
Expiry
X-Connection-Hash
Cross-Origin-Embedder-Policy
X-App-Version
X-GEO
Onion-Location
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Tumblr-Pixel-3
X-Cache-Expired-At
Alternate-Protocol
X-ID
X-Api-Version
CDN-RequestId
X-Client-Ip
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Cache-Server
X-PHP-Backend
Environment
X-Server-W
AMP-Access-Control-Allow-Source-Origin
Priority
X-Jobs
DB-Nickname
CF-IPCountry
Uber-Trace-Id
X-Proxy-Cache-Status
X-Fastly-Request-Id
X-DC
X-Cluster-Node
X-Cache-Action
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Fastcgi-Cache
X-LSADC-Cache
Cdn-Requestid
User-Cache-Control
X-Tt-Logid
X-Mg-Request-UUID
Sid
X-Tx-Id
X-MP-GENERATED-AT
X-Ismobilevalue
Edge-Cache
Fusion-Component-Id
Fusion-Content-Id
DCR-Processing-Time-Ms
Content-Secure-Policy
Surrogated-Key
A
Sslversion
Cache-Tv-Group
Fusion-Content-Source
Candidate-Md5Url
DCR-Decision-By
Fusion-Source
Origin
Origin-Agent-Cluster
Magicmarker
Ngx.Var.Host
Meta-Geo-Continent
Rendered-Blocks
Lang
MD5-Digest
Server-Host
Fusion-Template-Id
Gannett-Cam-Experience-Id
Req-ID
Fusion-Deployment-Id
X-Cache-NE
X-Node-Id
X-ND-Cache
X-Op-Id-All
X-Org
X-Powered-By-VTEX-Cache
X-Origin-Expires
X-NCache
X-Level-Front-Cache
X-Gzip
X-Generated-On
X-Hnp-Log
X-Ig-Origin-Region
X-Jungle-Id
X-Request-Start
X-Rojux
X-Vdms-Version
X-Vdms-Path
X-Viewer-Country
X-VTEX-Cache-Server
X-Vtex-Remote-Cache
X-VTEX-Cache-Time
X-Varnish-Hostname
X-UA-Device-Type
X-ScT
X-SB
X-SRCache-Key
X-Thanos
X-TIM-N
X-Gen-Mode
X-Forwarded-Site
X-A-Wwc
X-A-Dgt
X-Aed
X-Bc-Bl
X-Bip
X-BCube-Filmed-By
X-A-Dcw
X-A-Dam
Wxu-Next-Hostname
Vix-Hermes-Req-Id
Wxu-Next-Region
X-A
X-A-Ccd
X-Bl-Debug
X-Block-Status
X-Ec-Fail
X-Dispatcher-Server
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-FB-TRIP-ID
X-Esi-Check
X-Device-Os
X-Developer
X-Clientip
X-Cache-Id
X-Conf
X-Content-Age
X-D
T-Server
Wxu-Next-Commit
X-Original-Request-Id
X-Varnish-Beresp-Ttl
HostName
X-Response-Served-From
X-Uri
X-Zone
X-Origin-Response-Time
Yak-Timeinfo
X-Cache-TTL-Remaining
Host-ID
X-Mvc-Supplant-Cachable
X-Loc
Server-Hostname
X-Core-Value
Sever-Int
X-Cdn-Srv
X-NMSegId
X-Policy
X-Cache-Info
X-Proto
X-Cache-Bucket
X-Platform
X-PAYTM-SRV-ID
X-HS-Content-Campaign-Id
X-Nyt-Route
X-Origin-Time
X-Nginx-Cache-Key
X-HN
Powered-By
X-FC-Vary-Parameters
X-Fmm-Version
PFcat
X-Fastly-Cache
X-Debug-Cache-Fetch
Release
X-Edge-Server
X-Debug-Cache-Store
X-CUA
Origin-EX
NM-Fastcgi-Cache
X-GeoIP-City
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-GeoIP
X-Geo-Header
Origin-CC
Server-Ext
X-Gdpr
X-Pubstack
Fastly-SSL
X-Var-Ttl
C-Via
X-App-Name
X-Amz-Storage-Class
Cache-Provider
X-V-Cache
Cdn-Host
Fastly-Backend-Name
X-Test
X-Auth-Group-Type
X-Varnish-Director
X-VarnishDD-TTL
X-Via-Fastly
X-WA-Info
XM
X-Service
X-VG-WebCache
X-AK-Request-ID
AKAMAI
X-Varnishpool
X-Ig-Push-State
Cdn-Request-Time
CDCHOST
X-Request-Time
Content-Style-Type
Cdncip
Content-Script-Type
X-Req
X-Region-Sid
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
DSUID
X-SD-PageType
X-Scheme
Cdnsip
X-Auto-Login
X-Backend-Instance
X-TT-LOGID
X-Ad-Load-Variation
X-DPWN-IS-SECURE
X-Aicache-OS
X-Acquia-Purge-Cdn-Unconfigured
X-CGP
X-Csrf-Jwt
X-BBC-Edge-Cache-Status
X-Cache-Backend
X-B3-Trace-ID
X-Cache-Aspx
X-Contensis-Viewer-Groups
X-Mvc-Supplant-OutputCached
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-Server-IP
X-Request-Host
X-Section
WP-Super-Cache
X-Varnish-Authentication
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-We-Are-Hiring
X-VG-TLSProxy
X-Varnish-Beresp-Status
X-Proxied-Request
X-Pool
X-From
Odigeo-Trace-Id
X-LiteSpeed-Cache-Control
X-Fastly-Backend
X-Eu-Site
X-Human
X-Tb-Optimization-Total-Bytes-Saved
X-Mly-Id
X-Access
X-Micro-Cache
X-Men
X-Location
X-Ec-Custom-Error
X-GoCache-CacheStatus
Tube-Get-Contents
Click-Count-Action-Start
True-Client-Country-4JS
RNT-Time
Tube-Got-Eval
Click-Count-Error
X-ECache
Tube-Return
Cluster
Adler-Geo
On-Server
Canary
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Redirect-Candidate
Apple-News-Services-Host
Producers
Pramga
Ssr
Cache-Key
Platform
Country-Code
Tube-Got-Results
Fastly-GeoIP-CountryCode
Req-Svc-Chain
Web-Mar-Region
We-Hiring
L5d-Success-Class
L
Gh-Request-Id
Ha-Gx-Prefs
HA-Ipaddr
Is-Eu
Esi-Enabled
Machine
Mail-Subject
V-Age
RNT-Machine
Apple-News-Services-Handled
W
X-PERF
Proxy-Firewall
X-Date
X-Custom-Header
X-Slack-Shared-Secret-Outcome
X-Accel-Expires-Debug
X-Hash
X-CacheTTL
X-NodeID
X-Slack-Backend
X-Up
X-Render-Time
NGX
X-ApacheServer
X-AIR-PT
X-Newrelic-Synthetics
Debug
X-LB-ID
SID
X-Varnish-Hits
X-NGINX-Cache
Fastly-Drupal-HTML
X-CACHE-AGE
X-DefHash
X-COUNTRY
X-Varnish-CookieINHashed-On
X-DefElseHash
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Nananana
X-Dc
Mime-Version
X-Pad
X-TIME
X-HA-Backend
X-Depends
X-HITS
X-CACHE-GROUP
CloudFront-Viewer-Country
X-Cs
Datacenter
X-Via-Popv
X-Via-Poph
X-Via-Popn
Pics-Label
X-Nf-Request-Id
X-Akamai-Transformed
X-Servedbyhost
X-Refresh
Locid
GeoIP-Latitude
X-Cache-FS-Status
X-Amz-Meta-Cb-Modifiedtime
X-VC-TTL
X-VHOST
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-LB-NoCache
X-Datadome
X-M-Reqid
X-Parent-Response-Time
X-M-Log
X-CS
X-Old-Content-Length
X-Cached-By
X-B3-Parentspanid
Ngx-Var-Key
X-Litespeed-Tag
X-LiteSpeed-Tag
Server-ID
Resin-Trace
Cdn
BehaviorPad-Version
X-CDN-Cache-Status
X-TH-Server
Server-Info
X-Wa
X-Moov-T
X-Nc
X-Moov-Xdn-Version
X-DynaTrace-JS-Agent
Cf-Ipcountry
Fastly-Drupal-Html
Cross-Origin-Embedder-Policy-Report-Only
GeoIp-Country-Code
X-APP
X-Vc
X-Presslabs-Stats
X-Vgn-Hpd-Reason
X-Fpc
X-IAuth-Set-Uid
X-VCache
NtCoent-Length
X-S-Cookie
X-External-Request-Id
Cf-Device-Type
X-User
X-Destination
X-B-Cookie
X-Content-Length
X-ZONE
X-NewRelic-App-Data
FSS-Cache
X-Application
X-CACHE-KEY
Serverhost
True-Client-Ip
X-Esi
Uri
X-Zen-Fury
True-Client-IP
CDN
X-HostName
X-TX-ID
X-Dynatrace-Js-Agent
X-Rocket-Build-Number
X-Varnish-Beresp-TTL
X-Sigma-Backend
X-Instance-Name
X-Cache-Date
X-Sigma
X-Srv
S-Rt
Vc-Max-Age
GeoIP-Country-Code
X-Is-Crawler
X-VServer
X-Dispatcher-Number
X-Aspnet-Duration-Ms
X-API-Version
X-Providence-Cookie
Tcn
Load-Balancing
X-Route-Name
X-Flags
X-DynaTrace
X-Oracle-DMS-ECID
Srv
X-Cdn-Cache-Status
X-Segment-20210421
X-Branch-Name
X-HOST
X-RequestId
Hostname
Request-ID
X-Dispatch
X-WA
Product
X-FPC
X-NC
X-Page-View
Ohc-File-Size
X-Cdn-Forward
X-DataCenter
X-B3-Spanid
X-APP-VERSION
Srvid
X-FL-QIT-DEBUG
X-Webkit-Csp-Report-Only
ServerName
X-Ckpd-Fst-Backend
Server-Id
Type
Geoip-Latitude
X-Geo
X-Http-Reason
X-Sql-Duration-Ms
X-Bug-Bounty
X-Sql-Count
X-SERVER-NAME
X-Lb-Nocache
X-Irp-Debug
Cl-Cache
CacheControlHeader
DataCenter
X-ServedByHost
X-VCL-Version
X-SIPLIST1
IsBot
X-Via-Edge
Edge-Copy-Time
Cloudfront-Viewer-Country
Epwk-X-Cache
X-Via-SSL
X-Via-CDN
Origin-Trial
X-Owner
Ohc-Cache-HIT
X-Cache-Ttl
WZWS-RAY
X-App
X-Correlation-ID
X-Via-PopH
Cross-Origin-Opener-Policy-Report-Only
XkeyRZ
MIME-Version
X-Ua
X-Proxy-CacheRZ
X-Core-Mission
X-Via-PopV
X-Via-PopN
PICS-Label
X-Ha-Backend
X-Nf-Language
X-Srcache-Store-Status
X-Nf-Ats-Version
X-Srcache-Fetch-Status
X-Nf-Country
Rtss
X-HubSpot-Correlation-Id
X-Hit
X-Vmg-Version
X-Limited
User-Agent
N-Cache
Cneonction
X-MSEdge-Flight
X-Akamai-Device-Characteristics
ServerHost
X-MSEdge-Features
X-CSRF-TOKEN
X-Qloud-Router
X-MiniProfiler-Ids
X-Lb-Id
Lb
X-Fastly-Country-Code
CountryCode
X-Service-Response-Time
X-Amz-Meta-Opti
X-Info
Sm-Log-Id
X-Web-Server
X-Acquia-Application-UUID
X-Gamma-Serve
X-Datacenter
Cmstype
X-Acquia-Application-Trace
X-Sqd-Stime
X-Sqd-Ctime
Cmsid
X-Acquia-Purge-Tags
X-Acquia-Site
Warning
Servername
X-Litespeed-Cache-Control
X-LAGOON
Xkey-La3
X-Check-Cacheable
X-Serial
Xkeylog
X-Akamai-Pragma-Client-IP
X-Requestid
X-Th-Server
X-RAMCache
X-Snapshot-Date
Ngx
X-Amz-Meta-S3b-Last-Modified
X-Udemy-Cache-App-Namespace
X-Proxy-Cache-La3
X-Dw-Trace-Id
X-Amz-Meta-Sha256
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Ramcache