Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-Xss-Protection
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Request-ID
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
Permissions-Policy
X-Ws-Request-Id
Xkey
X-Rq
X-Age
X-Vhost
X-Amz-Version-Id
X-Dispatcher
Allow
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-OneAgent-JS-Injection
X-Device
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Server-Id
X-WebKit-CSP
X-Host
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Ruxit-JS-Agent
Content-Location
X-Application-Context
X-Node
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
P3p
X-NWS-LOG-UUID
X-Country
X-CST
Service-Worker-Allowed
X-Country-Code
X-Litespeed-Cache
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
Rating
X-Rack-Cache
X-Url
X-Amz-Server-Side-Encryption
Nginx-Cache
X-FTR-Request-ID
X-Times
X-TtlSet
X-PC
X-Vname
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Oneagent-Js-Injection
X-Server-Name
X-Edge
X-Browser-Type
X-Mcache
X-Midtier
X-Webkit-Csp
X-Powered-By-Plesk
X-Cnection
X-ESI
X-GitHub-Request-Id
X-Upstream
X-ECACHE
Edge-Control
X-Element-Page-Cache
X-D2id
X-Ac
Verso
X-MS-InvokeApp
AR-ATIME
AR-Request-ID
AR-SID
AR-PoweredBy
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-FastCGI-Cache
X-Ser
Accept-Ch-Lifetime
X-Vcap-Request-Id
X-Cache-TTL
X-Abt-Application-Version
X-B3-TraceId
X-Navigation-Version
AR-CACHE
X-Dw-Request-Base-Id
X-Mod-Pagespeed
X-NF-Request-ID
SPIisLatency
SPRequestDuration
X-Aws-Lambda-Call-Status
SPRequestGuid
X-SharePointHealthScore
Fastly-Restarts
X-Amz-Rid
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev
X-Middleton-Display
X-Sol
Display
Pagespeed
X-Mg-S
Edge-Cache-Tag
X-Ruxit-Js-Agent
X-Edge-Location-Klb
X-Kinsta-Cache
X-Client-IP
S
X-Powered-CMS
Response
Cache-Status
X-Middleton-Response
X-Amzn-Trace-Id
X-Goog-Hash
X-Version
Access-Control-Request-Method
X-VARITI-CCR
X-Fastly-Request-ID
X-ARC
RTSS
X-Cache-Key
X-RateLimit-Remaining
X-Content-Digest
X-TraceId
Cross-Origin-Resource-Policy
X-Recruiting
X-Forwarded-For
X-Ratelimit-Limit
X-T
X-Varnish-TTL
Realpath
X-Correlation-Id
X-MSEdge-Ref
Front-End-Https
Fastcgi-Cache
X-Cached
X-PDP-UNCACHING-HASH
MS-Author-Via
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Ratelimit-Remaining
Content-MD5
X-TTL
X-Ua-Browser
X-FTR-Balancer
X-HS-Cache-Config
X-HS-Hub-Id
X-FTR-Backend-Server
X-FTR-Backend
X-HS-Content-Id
X-Protected-By
X-Shield-Request-Id
X-Country-Code-Real
X-FTR-Cache-Status
X-Request-Processing-Time
Public-Key-Pins
X-Request-Received
Payment
X-Forwarded-Proto
Server-Node
X-LLID
X-Frontend
TP-Cache
Arr-Disable-Session-Affinity
X-SRCache-Store-Status
X-HS-Combine-CSS
X-SRCache-Fetch-Status
MicrosoftSharePointTeamServices
X-Distributor
X-FTR-Expires
X-Accel-Expires
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ttl
Count-Hit
X-ORACLE-DMS-RID
X-Server-ID
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-GUploader-UploadID
X-Origin-Server
X-LB-Cache
X-NODE
X-Ezoic-Cdn
X-Microsite
X-Request-Handler-Origin-Region
X-TEC-API-VERSION
X-Origin-Cache-Key
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Az
X-AppVersion
X-Content-Security-Policy-Report-Only
X-Activity-Id
Host
X-Www-Served-By
X-PressLabs-Stats
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Varnish-Server
X-App-Server
X-Varnish-Backend
X-Cluster-Name
Retry-After
Accept-Charset
Cache-Tags
X-Amz-Meta-S3cmd-Attrs
X-Ua-Device
Server-Name
X-Hits
X-Newrelic-App-Data
Cleartype
X-Geo-Country
X-Hostname
X-Envoy-Decorator-Operation
X-NGENIX-Cache
X-Goog-Metageneration
Referer-Policy
X-CSRF-Token
X-ORACLE-DMS-ECID
X-Upgrade-Enabled
X-DIS-Request-ID
TP-L2-Cache
X-Seen-By
X-Azure-Ref
X-Git-Hash
TCN
Access-Control-Allow-Method
X-Unique-Id
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Filterid
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-F-Cache
X-Proxy
X-Load-Cache
X-Id
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Revision
X-Cache-Control
Section-Io-Cache
X-Request-Guid
X-Trace-Id
DC
X-B
X-B3-Sampled
X-TT
Healthy
X-Grace
X-Px
X-Type
X-Debug-Info
Paypal-Debug-Id
X-Page-Id
X-Contextid
X-Fb-Rlafr
X-FB-Debug
X-Logged-In
X-N
X-Mobile
X-Debug
X-Oracle-Dms-Ecid
Viewport
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-RateLimit-Limit
X-Whom
X-Goog-Stored-Content-Length
Fastly-SWR
Fastly-SIE
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-XRDS-LOCATION
X-Varnish-Ttl
X-Datadog-Sampling-Priority
Charset
X-Template
X-Oracle-Dms-Rid
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Content-Options
Content-Disposition
Version
X-Via-JSL
X-Cache-Grace
X-Wix-Request-Id
X-Webkit-CSP
X-App-Environment
X-Magnolia-Registration
X-Varnish-Grace
X-EdgeConnect-Cache-Status
X-Origin-Cache
X-Language
X-B-Cache
X-Signature
X-B3-SpanId
X-Node-Name
X-Time
X-Rid
X-RemovedCookies
X-ProcessESI
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
SRV
X-Debug-IsPreview
X-Debug-IsConnected
X-Datadog-Sampled
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-Yottaa-Metrics
X-Tumblr-Pixel-0
SD-X-WS
Ms-Operation-Id
X-RTag
X-G
X-UUID
X-Rule
MS-CV
X-Amz-Replication-Status
GEO-INFO
ServerID
X-FW-Serve
X-FW-Version
X-Hl-Ver
X-Instance
X-Storage
X-FW-Static
X-FW-Server
X-Adobe-Loc
X-FW-Dynamic
X-FW-Hash
X-Adobe-Content
X-FW-Type
X-Amzn-Remapped-Content-Length
X-NYM-Debug-Backend
NGB
X-Is-Bot
X-Cacheable-TTL
Liferay-Portal
X-Rendered-As
X-Device-Type
X-L-Path
X-Region
X-Status
X-Proxy-Cache-Info
X-RateLimit-Reset
X-Backend-Name
X-IPS-LoggedIn
X-Cache-Hit
X-Environment-Context
X-User-Agent
Country
X-Source
X-Real-IP
Countrycode
Surrogate-Key
X-NWS-UUID-VERIFY
X-URL
X-ServerID
Akamai-GRN
Amp-Access-Control-Allow-Source-Origin
X-Sucuri-ID
X-WP-CF-Super-Cache-Active
X-Sucuri-Cache
Cross-Origin-Window-Policy
X-Cache-Age
X-Servername
OT-Force-Account-Verify
X-UA
From-Origin
X-VC-Cache
X-RM-Cache-TTL
X-WebKit-CSP-Report-Only
Front
Backend
X-Air-Pt
X-Framework
Upgrade-Insecure-Requests
X-INCAP-ABP
X-Mode
X-Wormhole-Sdk
Refresh
X-AB
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Cache-Time
X-Akamai-Request-ID2
X-Content-Powered-By
X-Xrds-Location
X-DataDome
X-Nginx-Cache
X-Handled-By
Xet-Cookie
X-Edge-Location
Frame-Options
Url
X-HTML-Minification-Powered-By
X-Endurance-Cache-Level
Selected-Fe
Meta-Geo
Filters
X-JoinUs
X-CDN-Forward
X-SRV
X-Origin-CC
X-Xfnlog-Site
X-Vcache
X-Rn-Rsrv
X-Timing-Wait
X-Proxy-Build
X-Origin-TTL
X-Rewrite-Enabled
X-SaId
X-RCS-CacheZone
X-UPSTREAM-Address
X-Webstats-RespID
Access-Control-Request-Headers
TWC-Connection-Speed
X-Cache-Operation
X-Drupal-Cache-Tags
TWC-Device-Class
X-Container-Uri
X-Logging-Id
WPO-Cache-Message
TWC-GeoIP-LatLong
WPO-Cache-Status
Property-Id
X-Labrador-Cache-Channel
X-LJ-Flow-ID
TWC-GeoIP-Country
Webcakes-Region
X-Tumblr-Pixel-2
X-Provided-By
Webcakes-App-Version
Atl-Traceid
X-AWS-Id
X-Akamai-Edgescape
X-Origin
Accept-Language
X-Git-Commit
X-Served-From
X-PHP-Host
X-Cache-Rule
TWC-Privacy
Cache
X-VWS-Id
X-Origin-Hint
TWC-Locale-Group
Webcakes-App-Name
X-Redis-Cache
X-Drupal-Cache-Contexts
X-Restarts
X-Web-Node
X-Zipkin-Id
X-Fetched-On
X-Extlb
X-Azure-Ref-OriginShield
X-Reqid
X-Cloudmap
X-No-Session
Web-Mar-Node
X-Proxied
Thinkindot-Control
Thinkindot-CacheControl
X-CMSURLCustom
X-Thinkindot-L3
X-Buckets
X-Adobe-Source
X-Origin-Date
Webserver
X-Accel-Version
X-Tb
X-Scope-Id
TDXMobile
Thinkindot-CacheControl-Type
X-Locale
X-Hosted-By
X-XRDS-Location
X-Cluster
X-Cms-Context
X-Routing-Service
X-Cache-Debug
X-Varnish-Cache-Hits
X-Shield-Cache-Expires
ServedBy
X-Site-Version
Section-Io-Id
Mn-Server-Ip
Apigw-Requestid
X-Forwarded-Host
X-Format
X-Director
X-Generation-Time
X-Browser-Name
X-Geo-Region
X-Upstream-Ht
X-Frame-Option
Cache-Hits
X-Upstream-Ct
X-S
X-Tncms
X-Is-Tablet
X-Say-TTL
X-Soup
X-Lambda-Id
X-Skip-Cache
X-Loop
X-R9-Blue-Green-Version
X-VCT
X-Is-Supported-Browser
X-Varnish-Age
X-Is-Desktop
X-IPLB-Request-ID
X-IPLB-Instance
X-Is-Mobile
X-Tcp-Rtt
X-Say-Cacheable
X-SayCDN-TTL
X-ShardId
X-Cache-Host
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Httpd
X-ProxyCache-Key
X-ProxyCache-Status
X-Storefront-Renderer-Rendered
X-BYPASS-REASON
X-GeoCode
X-GeoCountry
X-Alternate-Cache-Key
X-Ms-Request-Id
X-Detected-As
X-Ms-Version
Xserver
X-ShopId
X-Shopify-Stage
X-Generated-By
X-Cdn-Origin
X-Varnish-Beresp-Grace
X-VC
X-Optimistic-Header
X-Cache-Status-Check
X-Rocket-Nginx-Serving-Static
X-RID
X-TA-CDN-Provider
X-Lagoon
LB
X-Ratelimit-Reset
X-Worker
X-Vercel-Id
X-Vercel-Cache
X-Request-URI
Azure-SiteName
Azure-SlotName
Azure-InstanceId
Azure-RegionName
Azure-Version
Source
Node
X-WP-CF-Super-Cache-Cookies-Bypass
Fastcgi-Useragent
X-B3-Traceid
Protected
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-PullZone
CDN-RequestCountryCode
X-Vcl-Version
X-Pass-Why
CDN-CachedAt
CDN-Cache
CDN-Uid
CDN-RequestPullSuccess
Cross-Origin-Embedder-Policy
Expiry
X-Connection-Hash
X-App-Version
Onion-Location
X-GEO
X-Tumblr-Pixel-3
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Cache-Expired-At
X-ID
Alternate-Protocol
X-Cache-Server
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Client-Ip
CDN-RequestId
DB-Nickname
X-Api-Version
Environment
X-PHP-Backend
X-Jobs
Priority
AMP-Access-Control-Allow-Source-Origin
X-Server-W
CF-IPCountry
X-Proxy-Cache-Status
X-DC
X-Cache-Action
Uber-Trace-Id
X-Fastly-Request-Id
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
User-Cache-Control
X-Cluster-Node
X-Fastcgi-Cache
Cdn-Requestid
X-Tt-Logid
X-LSADC-Cache
X-MP-GENERATED-AT
X-Tx-Id
Sid
X-Mg-Request-UUID
Req-ID
Server-Host
X-Generated-On
Rendered-Blocks
X-Aed
Origin
X-Gen-Mode
X-Forwarded-Site
Ngx.Var.Host
X-BCube-Filmed-By
X-A-Wwc
X-Bc-Bl
Origin-Agent-Cluster
Surrogated-Key
X-Gzip
Wxu-Next-Commit
Wxu-Next-Hostname
Vix-Hermes-Req-Id
X-Ig-Origin-Region
X-Jungle-Id
HostName
Wxu-Next-Region
X-A
X-A-Dgt
T-Server
X-A-Dcw
X-GeoIP-City
X-A-Ccd
X-A-Dam
Sslversion
A
Fusion-Source
Fusion-Template-Id
Gannett-Cam-Experience-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
X-Content-Age
X-Conf
X-Cache-Id
MD5-Digest
Magicmarker
X-Cache-NE
X-Clientip
Meta-Geo-Continent
X-Level-Front-Cache
X-Block-Status
X-D
X-Ec-GeoHdr
Candidate-Md5Url
X-Ec-Fail
Cache-Tv-Group
X-Epic-Correlation-Id
X-FB-TRIP-ID
X-Esi-Check
X-Dispatcher-Server
X-Device-Os
DCR-Processing-Time-Ms
X-Bl-Debug
Edge-Cache
DCR-Decision-By
X-Bip
X-Developer
Content-Secure-Policy
Lang
X-Hnp-Log
X-Node-Id
X-Vdms-Version
X-SRCache-Key
X-Vdms-Path
X-UA-Device-Type
X-ScT
X-Original-Request-Id
X-Op-Id-All
X-SB
X-TIM-N
X-Thanos
X-Origin-Expires
X-Org
X-NCache
X-ND-Cache
X-Vtex-Remote-Cache
X-Powered-By-VTEX-Cache
X-Rojux
X-Varnish-Hostname
X-Viewer-Country
X-Response-Served-From
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Request-Start
X-Zone
X-Uri
X-Varnish-Beresp-Ttl
X-Origin-Response-Time
X-V-Cache
X-Varnish-Director
X-Var-Ttl
X-Cache-Bucket
X-Cdn-Srv
X-Loc
Fastly-Backend-Name
X-CUA
X-Scheme
Fastly-SSL
X-SD-PageType
X-Cache-TTL-Remaining
Host-ID
X-Test
X-Cache-Info
X-Backend-Instance
Server-Hostname
Server-Ext
X-Via-Fastly
X-VG-WebCache
Sever-Int
Ssr
X-Ig-Push-State
Yak-Timeinfo
XM
X-WA-Info
Release
X-AK-Request-ID
Origin-EX
Origin-CC
X-Varnishpool
NM-Fastcgi-Cache
PFcat
X-Auto-Login
X-Amz-Storage-Class
X-App-Name
X-Auth-Group-Type
Powered-By
X-VarnishDD-TTL
X-Core-Value
DSUID
X-Fmm-Version
X-Gdpr
X-PAYTM-SRV-ID
X-Fastly-Cache
C-Via
CDCHOST
X-RateLimit-Limit-Second
Cache-Provider
X-Edge-Server
X-Origin-Time
X-Service
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-HN
X-HS-Content-Campaign-Id
X-Nginx-Cache-Key
X-GeoIP
X-Nyt-Route
X-Geo-Header
X-NMSegId
Cdn-Host
AKAMAI
Content-Script-Type
Cdn-Request-Time
X-Region-Sid
Content-Style-Type
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Request-Time
X-RateLimit-Remaining-Second
X-Req
Cdncip
Cdnsip
X-TT-LOGID
X-Mly-Id
X-Cache-Backend
X-Access
X-GoCache-CacheStatus
X-Pubstack
X-Varnish-Authentication
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-Cache-Aspx
X-We-Are-Hiring
X-Tb-Optimization-Total-Bytes-Saved
Odigeo-Trace-Id
Web-Mar-Region
X-Location
X-Men
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Human
X-Acquia-Purge-Cdn-Unconfigured
X-Request-Host
X-Policy
X-FC-Vary-Parameters
X-SVT-ORM-VERSION
X-Platform
X-Pool
X-BBC-Edge-Cache-Status
X-Proto
X-Fastly-Backend
X-DPWN-IS-SECURE
X-B3-Trace-ID
X-From
X-VG-TLSProxy
X-Section
X-Ec-Custom-Error
X-Server-IP
X-Sn-Servicetimems
X-Contensis-Viewer-Groups
X-SVT-ORM-RULES
X-Proxied-Request
X-Ad-Load-Variation
X-Aicache-OS
Apple-News-Services-Handled
Adler-Geo
Producers
Apple-News-Services-Host
Machine
Redirect-Candidate
X-LiteSpeed-Cache-Control
Pramga
Platform
On-Server
X-ECache
Apple-News-Services-Parsed-Url
Is-Eu
Apple-News-Services-Request-Url
Cache-Key
X-Ismobilevalue
L
Click-Count-Action-Start
Tube-Return
Tube-Got-Results
Tube-Got-Eval
WP-Super-Cache
Cluster
Country-Code
V-Age
Tube-Get-Contents
Esi-Enabled
Fastly-GeoIP-CountryCode
Click-Count-Error
Req-Svc-Chain
True-Client-Country-4JS
RNT-Machine
RNT-Time
X-Eu-Site
L5d-Success-Class
Canary
X-Csrf-Jwt
Gh-Request-Id
Ha-Gx-Prefs
X-CGP
HA-Ipaddr
X-Render-Time
X-Up
X-Slack-Shared-Secret-Outcome
Proxy-Firewall
X-Varnish-Beresp-Status
X-Accel-Expires-Debug
We-Hiring
X-Custom-Header
X-NodeID
Mail-Subject
X-ApacheServer
X-Mvc-Supplant-OutputCached
X-Hash
NGX
X-Slack-Backend
X-PERF
W
X-Date
SID
X-Newrelic-Synthetics
X-AIR-PT
X-LB-ID
X-NGINX-Cache
Debug
X-CacheTTL
X-Varnish-Hits
Fastly-Drupal-HTML
X-CACHE-AGE
X-Nananana
X-COUNTRY
X-DefElseHash
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-DefHash
X-Dc
X-Varnish-Remaining-TTL
Mime-Version
X-HA-Backend
X-CACHE-GROUP
X-Cs
X-HITS
Datacenter
X-Via-Popv
X-Via-Popn
X-Via-Poph
CloudFront-Viewer-Country
Pics-Label
X-TIME
X-Depends
X-Pad
X-Nf-Request-Id
X-Servedbyhost
X-Refresh
Locid
X-VHOST
X-Amz-Meta-Cb-Modifiedtime
GeoIP-Latitude
X-Cache-FS-Status
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-Akamai-Transformed
X-Parent-Response-Time
X-Datadome
X-M-Log
X-LB-NoCache
X-VC-TTL
X-M-Reqid
X-CS
X-Cached-By
X-B3-Parentspanid
Ngx-Var-Key
X-Litespeed-Tag
X-Old-Content-Length
X-LiteSpeed-Tag
Server-Info
Resin-Trace
Server-ID
X-CDN-Cache-Status
Cdn
X-TH-Server
BehaviorPad-Version
X-Wa
GeoIp-Country-Code
X-Nc
X-Moov-T
X-Moov-Xdn-Version
X-DynaTrace-JS-Agent
Fastly-Drupal-Html
Cf-Ipcountry
Cross-Origin-Embedder-Policy-Report-Only
X-APP
X-Vc
X-Presslabs-Stats
X-Vgn-Hpd-Reason
NtCoent-Length
X-IAuth-Set-Uid
X-Fpc
X-VCache
X-User
Cf-Device-Type
X-B-Cookie
X-Destination
X-Application
X-External-Request-Id
X-S-Cookie
True-Client-IP
X-NewRelic-App-Data
X-Content-Length
FSS-Cache
X-ZONE
Uri
X-CACHE-KEY
Serverhost
X-Zen-Fury
X-Esi
X-SERVER-NAME
X-Dynatrace-Js-Agent
X-TX-ID
X-HostName
CDN
True-Client-Ip
X-Varnish-Beresp-TTL
X-Sigma-Backend
X-Instance-Name
X-Sigma
X-Srv
X-Cache-Date
X-Rocket-Build-Number
Load-Balancing
Vc-Max-Age
S-Rt
Tcn
X-Dispatcher-Number
X-Providence-Cookie
X-VServer
X-API-Version
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-DynaTrace
Hostname
X-Oracle-DMS-ECID
X-RequestId
X-HOST
Srv
X-Branch-Name
X-Segment-20210421
GeoIP-Country-Code
Request-ID
X-NC
X-Dispatch
X-Cdn-Cache-Status
X-FPC
X-WA
X-Page-View
Ohc-File-Size
X-Cdn-Forward
Product
X-DataCenter
X-B3-Spanid
X-APP-VERSION
Srvid
X-Webkit-Csp-Report-Only
Server-Id
X-Ckpd-Fst-Backend
Geoip-Latitude
X-FL-QIT-DEBUG
Type
X-Geo
X-Irp-Debug
X-Sql-Duration-Ms
X-Lb-Nocache
ServerName
X-Http-Reason
X-Sql-Count
X-Bug-Bounty
DataCenter
Cl-Cache
X-ServedByHost
X-VCL-Version
Ohc-Cache-HIT
X-Owner
CacheControlHeader
IsBot
Origin-Trial
Cloudfront-Viewer-Country
X-Via-Edge
Edge-Copy-Time
Epwk-X-Cache
X-SIPLIST1
X-Via-CDN
X-Via-SSL
X-Cache-Ttl
WZWS-RAY
X-App
X-Ua
PICS-Label
X-Via-PopH
X-Ha-Backend
XkeyRZ
X-Proxy-CacheRZ
MIME-Version
Cross-Origin-Opener-Policy-Report-Only
X-Core-Mission
X-Via-PopV
X-Via-PopN
X-Correlation-ID
X-Srcache-Fetch-Status
Rtss
X-Srcache-Store-Status
X-Limited
X-Nf-Ats-Version
ServerHost
User-Agent
X-Akamai-Device-Characteristics
X-Nf-Country
X-Hit
X-Vmg-Version
N-Cache
X-Nf-Language
Cneonction
X-HubSpot-Correlation-Id
X-MSEdge-Features
X-CSRF-TOKEN
X-Lb-Id
X-Qloud-Router
X-MSEdge-Flight
X-MiniProfiler-Ids
Servername
Lb
Warning
CountryCode
X-Acquia-Purge-Tags
Sm-Log-Id
X-Info
X-Service-Response-Time
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Fastly-Country-Code
Cmstype
X-Amz-Meta-Opti
X-Datacenter
X-Acquia-Site
Cmsid
X-Gamma-Serve
X-Sqd-Ctime
X-Sqd-Stime
X-Web-Server
X-LAGOON
X-Litespeed-Cache-Control
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-Serial
X-RAMCache
Xkey-La3
X-Akamai-Pragma-Client-IP
Xkeylog
X-Proxy-Cache-La3
X-Requestid
X-Check-Cacheable
X-Th-Server
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Sha256
Ngx
X-Snapshot-Date
X-Ramcache
X-Udemy-Cache-App-Namespace