Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Content-Security-Policy-Report-Only
Accept-CH
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Check
X-Drupal-Cache
X-Ua-Compatible
X-Generator
X-Cache-Status
Server-Timing
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
Cf-Edge-Cache
X-Amz-Id-2
X-Via
Host-Header
Permissions-Policy
EagleId
Keep-Alive
Request-Context
X-Cache-Group
X-Robots-Tag
X-Backend
X-UA-Device
X-AH-Environment
X-Hacker
X-Server
X-Proxy-Cache
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
Xkey
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Server-Powered-By
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
Allow
X-Varnish-Cache
P3p
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-WebKit-CSP
X-Host
X-Backend-Server
Cf-Railgun
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Server-Id
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
Surrogate-Control
X-Akam-SW-Version
X-HW
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
X-Node
Request-Id
X-Country
Content-Location
X-Nginx-Cache-Status
X-Application-Context
Accept-Ch-Lifetime
X-Nginx-Upstream-Cache-Status
X-Litespeed-Cache
X-ASPNET-VERSION
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Url
X-Trace
Cache-Tag
X-Clacks-Overhead
Rating
X-Amz-Server-Side-Encryption
X-Times
X-Rack-Cache
X-PC
X-TtlSet
X-Vname
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Server-Name
X-Daa-Tunnel
Nginx-Cache
X-FTR-Request-ID
Accept-Ch
X-Powered-By-Plesk
AR-Request-ID
AR-SID
AR-ATIME
AR-PoweredBy
X-Cache-TTL
X-Cnection
X-Ac
X-D2id
X-ESI
X-GitHub-Request-Id
X-Element-Page-Cache
X-CST
Edge-Control
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Exp-Id
X-Kinja-Server
Verso
X-Kinja
X-Kinja-Revision
X-GoogleNews-Bot
X-MS-InvokeApp
AR-CACHE
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Upstream
X-ECACHE
X-Dw-Request-Base-Id
X-Navigation-Version
X-FastCGI-Cache
Fastly-Restarts
X-Webkit-Csp
X-Oneagent-Js-Injection
SPIisLatency
SPRequestDuration
X-B3-TraceId
X-Mod-Pagespeed
X-Amz-Rid
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Instrumentation
X-PDP-UNCACHING-HASH
X-SharePointHealthScore
SPRequestGuid
X-Client-IP
X-ARC
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
Pagespeed
X-Sol
Display
X-Middleton-Display
X-Powered-CMS
X-Mg-S
S
X-Amzn-Trace-Id
Edge-Cache-Tag
Cache-Status
X-Version
Access-Control-Request-Method
X-Ratelimit-Limit
X-Middleton-Response
Response
X-VARITI-CCR
X-NF-Request-ID
RTSS
Realpath
X-Forwarded-For
X-T
X-Content-Digest
X-Cache-Key
Cross-Origin-Resource-Policy
X-Fastly-Request-ID
X-Ratelimit-Remaining
X-TTL
X-Ruxit-Js-Agent
X-Recruiting
Fastcgi-Cache
X-Cached
X-MSEdge-Ref
X-TraceId
X-ORACLE-DMS-RID
X-Correlation-Id
X-Shield-Request-Id
Front-End-Https
MicrosoftSharePointTeamServices
X-SRCache-Fetch-Status
X-Ua-Browser
X-SRCache-Store-Status
X-Forwarded-Proto
X-Varnish-TTL
X-RateLimit-Remaining
X-Request-Received
X-Request-Processing-Time
X-PressLabs-Stats
Arr-Disable-Session-Affinity
X-LLID
X-Protected-By
X-Frontend
TP-Cache
Payment
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
Server-Node
Public-Key-Pins
MS-Author-Via
Count-Hit
Content-MD5
X-Server-ID
X-Accel-Expires
X-GUploader-UploadID
X-HS-Combine-CSS
X-LB-Cache
X-Distributor
X-Newrelic-App-Data
X-Origin-Server
X-NODE
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Ezoic-Cdn
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
Surrogate-Key
X-ORACLE-DMS-ECID
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Microsite
X-Request-Handler-Origin-Region
X-Www-Served-By
X-FTR-Expires
X-Content-Security-Policy-Report-Only
X-App-Server
X-Activity-Id
X-AppVersion
X-Varnish-Server
Host
Cleartype
X-Az
Cache-Tags
X-B3-TraceId-Primal
X-Amz-Meta-S3cmd-Attrs
X-Ua-Device
X-Cluster-Name
Accept-Charset
Mrf-Cache-Status
MRF-Tech
X-Varnish-Backend
Retry-After
X-Goog-Metageneration
Filterid
X-Unique-Id
X-Ttl
X-Debug
X-Hits
Server-Name
Access-Control-Allow-Method
X-Git-Hash
X-Logged-In
X-Load-Cache
X-Azure-Ref
X-Upgrade-Enabled
X-Id
X-NGENIX-Cache
X-Envoy-Decorator-Operation
X-CSRF-Token
X-FB-Debug
X-Geo-Country
X-Hostname
TCN
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Proxy
X-TT
TP-L2-Cache
X-Tt-Trace-Host
X-B
X-Tt-Trace-Tag
Section-Io-Cache
Viewport
X-Grace
DC
X-Revision
X-Type
X-B3-Sampled
X-Seen-By
Healthy
X-Fb-Rlafr
X-Contextid
X-Cache-Control
X-Varnish-Ttl
X-Trace-Id
X-Time
X-Hcs-Proxy-Type
X-Request-Guid
X-F-Cache
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Fastly-SIE
X-Goog-Generation
Fastly-SWR
X-Mobile
X-N
X-XRDS-LOCATION
Content-Disposition
Referer-Policy
Paypal-Debug-Id
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Nf-Request-Id
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Varnish-Grace
X-Magnolia-Registration
X-Ratelimit-Reset
X-DIS-Request-ID
X-Webkit-CSP
X-Origin-Cache
X-Amz-Replication-Status
X-Via-JSL
X-Px
X-Page-Id
X-Debug-Info
X-Wormhole-Sdk
Version
X-Oracle-Dms-Ecid
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-G
X-UUID
X-ProcessESI
X-Whom
X-RemovedCookies
X-Rid
X-App-Environment
X-Debug-IsPreview
X-Tumblr-Pixel
X-Debug-IsConnected
X-Tumblr-User
X-Content-Options
X-Node-Name
X-Tumblr-Pixel-1
X-Rule
X-Tumblr-Pixel-0
X-Datadog-Sampled
X-Adobe-Loc
VIX-Pulpo-Node
X-RTag
MS-CV
Ms-Operation-Id
NGB
VIX-Pulpo-Upstream-Status
X-Hl-Ver
X-Adobe-Content
X-Storage
X-Source
X-Template
X-User-Agent
X-Region
X-Yottaa-Metrics
Cross-Origin-Window-Policy
X-Yottaa-Optimizations
X-Device-Type
X-Backend-Name
X-B-Cache
X-Proxy-Cache-Info
X-NYM-Debug-Backend
X-Signature
X-FW-Version
X-L-Path
X-FW-Serve
Country
X-FW-Static
X-FW-Type
X-Ismobilevalue
SD-X-WS
X-FW-Server
X-FW-Hash
X-Status
X-Cacheable-TTL
X-Wix-Request-Id
X-Environment-Context
X-Instance
X-FW-Dynamic
X-Is-Bot
X-NWS-UUID-VERIFY
X-Rendered-As
X-ServerID
Charset
X-Cache-Age
GEO-INFO
Countrycode
X-IPS-LoggedIn
Amp-Access-Control-Allow-Source-Origin
ServerID
X-RM-Cache-TTL
X-EdgeConnect-Cache-Status
SRV
Akamai-GRN
Front
X-Real-IP
X-Framework
X-Cache-Grace
X-WP-CF-Super-Cache-Active
Liferay-Portal
X-Amzn-Remapped-Content-Length
X-AB
X-Cache-Hit
X-Oracle-Dms-Rid
X-Language
X-WebKit-CSP-Report-Only
X-Content-Powered-By
X-Air-Pt
X-Akamai-Request-ID2
X-B3-SpanId
X-Api-Version
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
OT-Force-Account-Verify
X-Servername
X-VC
X-UA
X-Sucuri-Cache
From-Origin
X-VC-Cache
X-RateLimit-Limit
X-Sucuri-ID
Xet-Cookie
X-URL
X-Mode
X-Xrds-Location
X-Aws-Lambda-Call-Status
Backend
Accept-Language
Refresh
X-DataDome
Access-Control-Request-Headers
X-Cache-Status-Check
Webserver
X-Tt-Logid
X-ECache
Upgrade-Insecure-Requests
X-Nginx-Cache
X-HTML-Minification-Powered-By
X-Handled-By
X-Fastly-Request-Id
X-Cache-Time
X-JoinUs
X-UPSTREAM-Address
X-RCS-CacheZone
X-SaId
Meta-Geo
LB
Filters
X-Rn-Rsrv
X-Rewrite-Enabled
X-SRV
Property-Id
X-Varnish-Age
X-Labrador-Cache-Channel
Cache
X-Xfnlog-Site
X-Mg-Request-UUID
X-Webstats-RespID
X-Hosted-By
X-Origin-Hint
X-PHP-Host
X-Provided-By
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-R9-Blue-Green-Version
TWC-Locale-Group
X-Generated-By
TWC-GeoIP-Country
TWC-Privacy
X-Tumblr-Pixel-2
X-Origin-Date
ServedBy
X-S
Webcakes-App-Version
Webcakes-Region
TWC-Device-Class
X-Is-Mobile
X-Akamai-Edgescape
X-Forwarded-Host
X-Is-Supported-Browser
X-ProxyCache-Key
X-Is-Tablet
X-ProxyCache-Status
X-BYPASS-REASON
X-Git-Commit
X-Reqid
X-Browser-Name
X-Lambda-Id
X-Web-Node
X-Accel-Version
Atl-Traceid
X-Adobe-Source
Section-Io-Id
X-Served-From
X-Tb
X-Tcp-Rtt
X-Fetched-On
X-Locale
X-Logging-Id
X-Geo-Region
X-Container-Uri
X-Request-URI
X-Cluster
X-Cms-Context
X-Is-Desktop
X-Scope-Id
X-No-Session
X-Httpd
X-Skip-Cache
X-Shopify-Stage
X-Origin
X-Optimistic-Header
X-Loop
Selected-Fe
Web-Mar-Node
X-Cache-Operation
X-VCT
X-Varnish-Cache-Hits
X-IPLB-Instance
Apigw-Requestid
X-Alternate-Cache-Key
Mn-Server-Ip
X-Varnish-Beresp-Grace
X-Upstream-Ht
X-Frame-Option
X-Site-Version
X-Timing-Wait
X-Tncms
X-Upstream-Ct
X-Cache-Host
X-IPLB-Request-ID
X-Redis-Cache
Url
X-Cache-Debug
X-Restarts
X-Proxy-Build
X-Format
X-Cache-Rule
X-Storefront-Renderer-Rendered
X-Soup
X-Say-Cacheable
X-Extlb
X-AWS-Id
Xserver
X-Endurance-Cache-Level
X-Say-TTL
X-SayCDN-TTL
X-Vcl-Version
X-Ms-Version
X-Ms-Request-Id
X-Proxied
X-RID
X-Zipkin-Id
X-Routing-Service
X-VWS-Id
X-Cloudmap
X-LJ-Flow-ID
X-Edge-Location
X-Director
Onion-Location
X-INCAP-ABP
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Connection-Hash
Expiry
X-ShopId
X-ShardId
X-Detected-As
Frame-Options
X-GeoCountry
X-GeoCode
X-Azure-Ref-OriginShield
X-Cache-Expired-At
X-Vcache
X-Lagoon
Cdn-Requestid
Priority
X-CDN-Forward
Source
X-WP-CF-Super-Cache-Cookies-Bypass
WPO-Cache-Message
WPO-Cache-Status
Protected
X-Generation-Time
TDXMobile
Thinkindot-CacheControl-Type
X-Shield-Cache-Expires
Thinkindot-CacheControl
X-CMSURLCustom
X-B3-Traceid
Environment
X-Thinkindot-L3
Thinkindot-Control
X-Proxy-Cache-Status
Fastcgi-Useragent
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Cache-Action
X-Origin-CC
X-Origin-TTL
X-PHP-Backend
X-Cdn-Origin
X-Pass-Why
Uber-Trace-Id
CF-IPCountry
X-App-Version
Sid
X-Rocket-Nginx-Serving-Static
X-Worker
X-ID
X-Cluster-Node
X-Aspnetmvc-Version
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Vercel-Cache
X-Vercel-Id
Node
X-GEO
Cache-Hits
X-XRDS-Location
X-Buckets
X-FB-TRIP-ID
Cache-Tv-Group
X-Auth-Group-Type
CDN-Cache
CDN-EdgeStorageId
CDN-Uid
Cross-Origin-Embedder-Policy
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-PullZone
CDN-RequestPullSuccess
CDN-CachedAt
X-TA-CDN-Provider
AMP-Access-Control-Allow-Source-Origin
X-Fastcgi-Cache
X-Tumblr-Pixel-3
X-Server-W
X-Pad
X-Cache-Server
DB-Nickname
X-LiteSpeed-Cache-Control
X-A
X-Client-Ip
Alternate-Protocol
Magicmarker
X-Ec-GeoHdr
MD5-Digest
X-ND-Cache
X-TIM-N
X-V-Cache
X-GeoIP-City
Rendered-Blocks
X-Op-Id-All
X-Req
X-Service
X-Gzip
X-Org
X-Origin-Expires
X-Cache-TTL-Remaining
Origin-Agent-Cluster
X-Generated-On
Odigeo-Trace-Id
X-Rojux
Ngx.Var.Host
Sslversion
X-SRCache-Key
A
Surrogated-Key
X-Edge-Server
X-Epic-Correlation-Id
X-LSADC-Cache
X-ScT
Meta-Geo-Continent
X-Esi-Check
T-Server
X-Varnish-Remaining-TTL
X-DefElseHash
Gannett-Cam-Experience-Id
X-D
X-Dc
X-DefHash
DCR-Processing-Time-Ms
Cdn-Request-Time
Lang
DCR-Decision-By
X-Custom-Header
X-Core-Value
X-Ig-Push-State
X-Bl-Debug
X-Conf
Content-Secure-Policy
X-BCube-Filmed-By
X-Bc-Bl
X-Ig-Origin-Region
X-Cache-Id
X-Level-Front-Cache
X-Aed
X-Developer
X-Varnish-CookieINHashed-On
Wxu-Next-Hostname
Wxu-Next-Region
X-A-Ccd
X-Varnish-CookieHashed-On
X-Cache-NE
X-Ec-Fail
Candidate-Md5Url
Wxu-Next-Commit
X-Vdms-Version
X-A-Dam
X-A-Wwc
X-Vtex-Remote-Cache
X-Dispatcher-Server
Cdn-Host
X-A-Dgt
X-Viewer-Country
X-A-Dcw
X-Via-Fastly
Mime-Version
X-Jobs
X-GeoIP
Is-Eu
NM-Fastcgi-Cache
X-GoCache-CacheStatus
Host-ID
Fastly-Backend-Name
Esi-Enabled
Edge-Cache
Vix-Hermes-Req-Id
X-Amz-Storage-Class
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-AK-Request-ID
X-Aicache-OS
X-DPWN-IS-SECURE
X-Acquia-Purge-Cdn-Unconfigured
X-B3-Trace-ID
X-Backend-Instance
X-CacheTTL
X-Cache-FS-Status
X-Cache-Info
X-Cdn-Srv
X-Clientip
X-Content-Age
X-Bip
V-Age
Tube-Return
X-Gdpr
X-Fmm-Version
Req-ID
Producers
Powered-By
X-Geo-Header
Platform
X-Fastly-Cache
RNT-Machine
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Ssr
Server-Host
RNT-Time
X-Fastly-Backend
Origin
X-Platform
X-Tb-Optimization-Total-Bytes-Saved
X-SVT-ORM-VERSION
X-Loc
X-Test
X-Thanos
X-Tec-Api-Origin
X-UA-Device-Type
X-Sn-Servicetimems
X-Server-IP
X-Region-Sid
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Request-Time
X-Tx-Id
X-Scheme
X-SB
X-Tec-Api-Root
X-Tec-Api-Version
X-HN
PFcat
Cache-Provider
X-NodeID
HostName
XM
X-VarnishDD-TTL
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Varnish-Hostname
X-Varnish-Director
X-VG-TLSProxy
X-VG-WebCache
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Pubstack
X-SVT-ORM-RULES
Click-Count-Action-Start
X-NMSegId
X-Node-Id
Cdnsip
Adler-Geo
AKAMAI
X-Micro-Cache
Cdncip
X-Mvc-Supplant-Cachable
X-Mly-Id
X-Men
X-Nyt-Route
Content-Style-Type
Country-Code
X-Proto
Click-Count-Error
X-Policy
X-Powered-By-VTEX-Cache
X-PAYTM-SRV-ID
X-Origin-Time
Content-Script-Type
X-Varnish-Beresp-Ttl
X-HITS
X-DC
User-Cache-Control
CDCHOST
Fastly-SSL
HA-Ipaddr
Ha-Gx-Prefs
L5d-Success-Class
L
X-Csrf-Jwt
X-Eu-Site
X-Section
X-Location
Server-Info
X-Contensis-Viewer-Groups
Apple-News-Services-Request-Url
W
X-Access
X-CGP
True-Client-Country-4JS
X-Hash
X-GeoIP-Country-Code
X-Origin-Response-Time
X-GeoIP-Region-Code
X-Nginx-Cache-Key
X-Mvc-Supplant-OutputCached
X-SD-PageType
X-Pool
X-Forwarded-Site
X-Proxied-Request
X-Request-Start
X-FC-Vary-Parameters
X-Var-Ttl
X-Varnish-Authentication
Yak-Timeinfo
Apple-News-Services-Handled
Apple-News-Services-Host
X-Depends
X-HS-Content-Campaign-Id
X-We-Are-Hiring
X-Varnish-Beresp-Status
X-Varnishpool
X-Gen-Mode
X-Hnp-Log
Apple-News-Services-Parsed-Url
X-Date
Origin-CC
On-Server
NGX
Origin-EX
Release
We-Hiring
Req-Svc-Chain
Mail-Subject
Machine
Canary
Cache-Key
C-Via
Cluster
DSUID
Gh-Request-Id
Fastly-GeoIP-CountryCode
X-Accel-Expires-Debug
Proxy-Firewall
X-Cache-Aspx
X-Cs
X-BBC-Edge-Cache-Status
X-Block-Status
X-Cache-Bucket
X-App-Name
X-Auto-Login
X-AIR-PT
X-NGINX-Cache
BehaviorPad-Version
X-RateLimit-Reset
X-Ad-Load-Variation
X-Human
X-Slack-Backend
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
X-Slack-Shared-Secret-Outcome
X-Request-Host
Fusion-Component-Id
Debug
X-CUA
Server-Hostname
X-Ec-Custom-Error
Sever-Int
X-WA-Info
Server-Ext
Pramga
Web-Mar-Region
X-Varnish-Hits
X-Device-Os
X-LB-ID
Redirect-Candidate
X-Via-Popn
Fastly-Drupal-HTML
X-NCache
X-Via-Poph
X-Via-Popv
X-Up
X-MP-GENERATED-AT
X-APP
Pics-Label
X-From
X-HA-Backend
X-Zone
GeoIP-Latitude
X-LiteSpeed-Tag
X-Akamai-Transformed
X-Newrelic-Synthetics
CloudFront-Viewer-Country
X-Jungle-Id
X-Content-Length
X-VHOST
X-CACHE-AGE
X-Parent-Response-Time
SID
CDN-RequestId
X-Vdms-Path
X-Refresh
X-B3-Parentspanid
X-Cache-Backend
X-Servedbyhost
X-Origin-Cache-Key
X-Datadome
X-Nc
X-LB-NoCache
X-Nananana
Vc-Max-Age
WP-Super-Cache
X-CDN-Cache-Status
X-ZONE
Resin-Trace
X-CACHE-KEY
X-Uri
X-B3-Spanid
Fastly-Drupal-Html
X-DynaTrace-JS-Agent
X-Litespeed-Tag
X-RequestId
X-Wa
X-ApacheServer
Product
Datacenter
X-Dispatcher-Number
X-M-Log
X-M-Reqid
X-VC-TTL
Server-ID
X-PERF
X-Render-Time
NtCoent-Length
Cdn
X-Cached-By
X-Ckpd-Fst-Backend
GeoIp-Country-Code
X-Amz-Meta-Cb-Modifiedtime
X-CS
S-Rt
X-Fpc
Locid
FSS-Cache
X-Bug-Bounty
X-IAuth-Set-Uid
X-TX-ID
X-Varnish-Beresp-TTL
X-Esi
X-VCache
True-Client-Ip
ServerName
Serverhost
Uri
X-HubSpot-Correlation-Id
X-HostName
X-Srv
X-SERVER-NAME
X-Nf-Ats-Version
True-Client-IP
X-Nf-Language
X-Nf-Country
X-TT-LOGID
X-Response-Served-From
X-Old-Content-Length
GeoIP-Country-Code
X-CLOUD-TRACE-CONTEXT
Tcn
X-Original-Request-Id
X-TIME
Srv
X-Dynatrace-Js-Agent
User-Agent
X-Akamai-Device-Characteristics
X-FPC
Ngx-Var-Key
CDN
X-Vmg-Version
X-NewRelic-App-Data
Request-ID
X-Cdn-Forward
X-Info
X-Gamma-Serve
X-Cdn-Cache-Status
X-Vc
CacheControlHeader
ServerHost
X-Vgn-Hpd-Reason
X-WA
Cf-Ipcountry
Xc-Version
X-TH-Server
X-Hit
X-Moov-Xdn-Version
X-Moov-T
Server-Id
Hostname
X-APP-VERSION
X-COUNTRY
Expect-Staple
X-Webkit-Csp-Report-Only
Srvid
X-Correlation-ID
X-FL-QIT-DEBUG
X-Geo
X-NC
X-Platform-Router
X-Dispatch
X-Platform-Processor
X-Platform-Cluster
X-Presslabs-Stats
X-Amz-Meta-Opti
Geoip-Latitude
X-Lb-Nocache
Cf-Device-Type
X-S-Cookie
Cross-Origin-Embedder-Policy-Report-Only
X-User
X-ServedByHost
Cneonction
X-Limited
X-Destination
X-V
X-B-Cookie
X-Application
X-External-Request-Id
Cloudfront-Viewer-Country
X-VCL-Version
X-Oracle-DMS-ECID
X-Via-PopN
X-Ha-Backend
X-Zen-Fury
N-Cache
Origin-Trial
Permission-Policy
PICS-Label
X-Via-PopV
X-New
X-Platform-Server
X-Rollout
X-Via-PopH
X-Eligible
WZWS-RAY
X-Sigma-Backend
X-Proxy-CacheRZ
X-Sigma
Ohc-File-Size
X-Cache-Date
X-Ua
Epwk-X-Cache
X-Akamai-Pragma-Client-IP
X-MSEdge-Features
X-MSEdge-Flight
XkeyRZ
X-Rocket-Build-Number
X-Instance-Name
X-App
Rtss
X-Sqd-Ctime
X-Lb-Id
X-Sqd-Stime
X-ElasticPress-Query
X-VServer
X-API-Version
X-Serial
X-Check-Cacheable
X-MiniProfiler-Ids
X-Ftr-Request-Id
X-Internal-TTL
X-Branch-Name
X-Segment-20210421
X-Web-Server
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Lb
X-Via-Edge
X-Via-SSL
Timeexpire
X-VTEX-Cache-Backend-Header-Time
X-VTEX-Cache-Backend-Connect-Time
Cl-Cache
Edge-Copy-Time
X-Path
X-EC-Lua
X-Via-CDN
X-Service-Response-Time
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-Trace
Cmstype
Cmsid
Sm-Log-Id
X-Datacenter
X-CDN-Origin
CountryCode
X-Litespeed-Cache-Control
Servername
X-CSRF-TOKEN
X-LAGOON
Fl-Custom-Application
Ngx
IsBot
X-SIPLIST1
X-Traceid
X-RAMCache
X-Th-Server
X-Ramcache
X-Snapshot-Date
X-Udemy-Cache-App-Namespace
Ohc-Cache-HIT
X-IN-APIGATEWAYSSL
X-Origin-Upstream-Status
X-Sorting-Hat-Shopid
X-Shopid
X-Sorting-Hat-Podid
X-IN-APIGATEWAY
X-Dw-Trace-Id
X-Amz-Meta-Sha256
X-Amz-Meta-S3b-Last-Modified
X-Shardid
X-Fastly-Backend-Reqs
Wpo-Cache-Message
Wpo-Cache-Status
Warning