Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
Content-Security-Policy-Report-Only
X-Ua-Compatible
X-AspNet-Version
X-Runtime
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
P3p
X-Backend
X-UA-Device
X-Cache-Group
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
X-Age
Permissions-Policy
X-Vhost
X-Amz-Version-Id
Allow
X-Dns-Prefetch-Control
X-Dispatcher
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Cache-Lookup
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Host
X-Server-Id
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
Request-Id
X-Cloud-Trace-Context
X-Litespeed-Cache
X-Node
Content-Location
X-Application-Context
X-Ruxit-JS-Agent
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-CST
X-NWS-LOG-UUID
X-Country
Service-Worker-Allowed
X-Country-Code
X-Url
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Oneagent-Js-Injection
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Times
X-Server-Name
X-FTR-Request-ID
X-TtlSet
X-Vname
X-PC
X-Daa-Tunnel
X-Webkit-Csp
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-Cnection
X-ESI
X-Upstream
Edge-Control
X-MS-InvokeApp
X-GitHub-Request-Id
X-D2id
X-Element-Page-Cache
Verso
X-Ac
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Aws-Lambda-Call-Status
X-Exp-Variant
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
X-ECACHE
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Ser
X-Vcap-Request-Id
X-Navigation-Version
X-Cache-TTL
X-B3-TraceId
X-Abt-Application-Version
X-Mod-Pagespeed
SPRequestDuration
SPIisLatency
AR-CACHE
X-Ruxit-Js-Agent
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
Fastly-Restarts
X-NF-Request-ID
X-Client-IP
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Server-Lifecycle-Phase
X-Middleton-Display
X-Sol
Pagespeed
Display
Edge-Cache-Tag
X-Mg-S
S
X-Edge-Location-Klb
X-Kinsta-Cache
X-Powered-CMS
X-Amzn-Trace-Id
Response
X-Middleton-Response
Cache-Status
X-RateLimit-Remaining
X-VARITI-CCR
Access-Control-Request-Method
X-Cache-Key
X-Goog-Hash
X-Version
X-ARC
RTSS
X-Content-Digest
X-Fastly-Request-ID
X-TraceId
X-Forwarded-For
Cross-Origin-Resource-Policy
X-Recruiting
X-T
Realpath
X-Varnish-TTL
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Ttl
X-Correlation-Id
X-MSEdge-Ref
MS-Author-Via
Front-End-Https
X-Ratelimit-Limit
X-Cached
Fastcgi-Cache
Content-MD5
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Ua-Browser
X-FTR-Balancer
X-FTR-Backend
X-Protected-By
Server-Node
X-Country-Code-Real
Payment
X-FTR-Backend-Server
X-FTR-Cache-Status
Arr-Disable-Session-Affinity
X-Request-Processing-Time
X-Request-Received
X-PDP-UNCACHING-HASH
Public-Key-Pins
MicrosoftSharePointTeamServices
X-LLID
X-Shield-Request-Id
X-Frontend
X-Forwarded-Proto
X-HS-Combine-CSS
X-SRCache-Store-Status
TP-Cache
X-SRCache-Fetch-Status
X-Origin-Cache-Key
X-Distributor
X-Accel-Expires
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Jurisdiction
X-HP-Trace-Id
X-FTR-Expires
X-Server-ID
X-HP-Webp
Count-Hit
X-GUploader-UploadID
X-Hits
X-Origin-Server
X-Ratelimit-Remaining
X-LB-Cache
X-Ezoic-Cdn
X-ORACLE-DMS-RID
X-Request-Handler-Origin-Region
X-Microsite
X-Content-Security-Policy-Report-Only
X-AppVersion
X-Az
X-Activity-Id
Host
X-Varnish-Backend
X-TTL
X-TEC-API-VERSION
X-Www-Served-By
X-PressLabs-Stats
X-Cluster-Name
X-B3-TraceId-Primal
MRF-Tech
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ua-Device
Mrf-Cache-Status
Retry-After
Cache-Tags
X-Varnish-Server
X-App-Server
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
X-Id
Server-Name
X-Hostname
X-NGENIX-Cache
X-ASPNET-VERSION
X-Geo-Country
Cleartype
X-NODE
X-Envoy-Decorator-Operation
Referer-Policy
X-DIS-Request-ID
X-Newrelic-App-Data
X-Goog-Metageneration
X-Upgrade-Enabled
TP-L2-Cache
X-Seen-By
X-CSRF-Token
X-Amzn-RequestId
X-Azure-Ref
X-Oracle-Dms-Ecid
X-Git-Hash
Access-Control-Allow-Method
X-Amz-Apigw-Id
X-RateLimit-Limit
TCN
X-F-Cache
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Load-Cache
X-CCDN-CacheTTL
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Unique-Id
X-Proxy
X-Grace
X-ORACLE-DMS-ECID
Healthy
X-Debug-Info
X-Revision
Filterid
X-Px
X-Cache-Control
Paypal-Debug-Id
Section-Io-Cache
X-XRDS-LOCATION
X-Trace-Id
X-Request-Guid
X-B
X-TT
X-B3-Sampled
X-FB-Debug
DC
X-Type
X-Fb-Rlafr
X-Contextid
X-Oracle-Dms-Rid
X-Page-Id
X-N
X-Logged-In
X-Mobile
X-WP-CF-Super-Cache-Cache-Control
Viewport
X-WP-CF-Super-Cache
X-Debug
X-Whom
X-Varnish-Ttl
X-Template
Charset
Fastly-SIE
Fastly-SWR
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Time
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Language
X-Cache-Grace
X-Content-Options
X-Webkit-CSP
Version
X-Via-JSL
X-Magnolia-Registration
Content-Disposition
X-RateLimit-Reset
X-Wix-Request-Id
X-App-Environment
X-EdgeConnect-Cache-Status
X-Varnish-Grace
X-Signature
X-B-Cache
X-Node-Name
X-Origin-Cache
X-ProcessESI
VIX-Pulpo-Node
X-Amzn-Remapped-Content-Length
X-RemovedCookies
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Datadog-Sampled
X-Debug-IsConnected
X-Yottaa-Optimizations
X-Debug-IsPreview
X-Yottaa-Metrics
X-Tumblr-Pixel
X-Rule
SD-X-WS
X-Amz-Replication-Status
X-Hl-Ver
X-G
X-RTag
X-Backend-Name
X-UUID
Ms-Operation-Id
MS-CV
ServerID
GEO-INFO
X-FW-Serve
X-FW-Type
X-Instance
X-Proxy-Cache-Info
X-Storage
X-FW-Static
X-FW-Server
X-Adobe-Loc
X-Device-Type
X-FW-Dynamic
X-FW-Hash
X-Adobe-Content
X-FW-Version
X-Region
X-Cache-Age
X-Cacheable-TTL
X-IPS-LoggedIn
SRV
Liferay-Portal
X-User-Agent
NGB
Country
X-B3-SpanId
X-Environment-Context
X-Cache-Hit
X-L-Path
X-Status
X-Is-Bot
X-Rendered-As
X-NYM-Debug-Backend
X-Real-IP
X-Source
X-NWS-UUID-VERIFY
Countrycode
X-ServerID
X-Rid
Surrogate-Key
Akamai-GRN
X-Servername
X-Sucuri-Cache
X-Sucuri-ID
OT-Force-Account-Verify
X-WP-CF-Super-Cache-Active
From-Origin
Cross-Origin-Window-Policy
X-VC-Cache
X-UA
X-WebKit-CSP-Report-Only
X-RM-Cache-TTL
Backend
Upgrade-Insecure-Requests
Amp-Access-Control-Allow-Source-Origin
Front
X-Framework
X-INCAP-ABP
X-Mode
X-Xrds-Location
X-Air-Pt
Refresh
Frame-Options
X-AB
X-Cache-Time
X-HTML-Minification-Powered-By
X-Buckets
X-Akamai-Request-ID2
X-Air-Hostname
X-Content-Powered-By
Xet-Cookie
X-Air-Source
X-Air-Trace-Id
X-DataDome
X-RID
X-Handled-By
Url
X-Edge-Location
X-Endurance-Cache-Level
X-Wormhole-Sdk
X-VC
Webserver
X-Origin-CC
X-Xfnlog-Site
X-Cluster
Filters
X-Proxy-Build
X-Azure-Ref-OriginShield
X-Origin-TTL
X-JoinUs
X-LJ-Flow-ID
X-UPSTREAM-Address
X-Webstats-RespID
X-Vcache
X-RCS-CacheZone
X-Rewrite-Enabled
X-Reqid
X-AWS-Id
X-SaId
X-No-Session
Selected-Fe
Access-Control-Request-Headers
X-Rn-Rsrv
Meta-Geo
X-Akamai-Edgescape
X-VWS-Id
X-Timing-Wait
X-Origin-Date
X-Origin
X-Cache-Operation
Webcakes-App-Version
X-Tumblr-Pixel-2
TWC-Connection-Speed
X-Origin-Hint
X-PHP-Host
TWC-Device-Class
ServedBy
X-Labrador-Cache-Channel
TWC-GeoIP-Country
X-Cache-Rule
X-R9-Blue-Green-Version
X-IPLB-Request-ID
X-Served-From
Webcakes-App-Name
X-IPLB-Instance
Atl-Traceid
X-Ms-Version
X-Ms-Request-Id
X-Container-Uri
Property-Id
WPO-Cache-Message
WPO-Cache-Status
X-VCT
Mn-Server-Ip
TWC-Privacy
TWC-Locale-Group
X-Fetched-On
X-SRV
X-Generation-Time
X-Provided-By
Webcakes-Region
TWC-GeoIP-LatLong
X-Logging-Id
X-Git-Commit
X-Drupal-Cache-Tags
Web-Mar-Node
X-Httpd
Section-Io-Id
X-Drupal-Cache-Contexts
X-CMSURLCustom
X-Cms-Context
X-Cloudmap
X-Extlb
TDXMobile
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Cache-Debug
X-Hosted-By
Thinkindot-CacheControl
Cache
X-Restarts
X-Web-Node
X-Locale
X-Site-Version
X-Scope-Id
X-Adobe-Source
X-Tb
X-Accel-Version
X-Zipkin-Id
X-Varnish-Cache-Hits
X-CDN-Forward
X-Thinkindot-L3
X-Redis-Cache
X-Proxied
X-Shield-Cache-Expires
X-Routing-Service
X-Cache-Status-Check
X-Upstream-Ct
X-Cdn-Origin
X-Loop
X-Director
X-Tncms
X-Say-TTL
X-BYPASS-REASON
X-Browser-Name
X-Varnish-Age
X-S
X-Tcp-Rtt
X-Is-Desktop
X-Say-Cacheable
X-Soup
Apigw-Requestid
X-SayCDN-TTL
X-Upstream-Ht
X-Geo-Region
X-ProxyCache-Status
X-Skip-Cache
X-ProxyCache-Key
X-Is-Tablet
X-Lambda-Id
X-Forwarded-Host
X-Format
X-Is-Mobile
X-Frame-Option
X-Is-Supported-Browser
Cache-Hits
X-GeoCountry
X-ShopId
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Shopify-Stage
X-Varnish-Beresp-Grace
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
Xserver
X-Alternate-Cache-Key
X-ShardId
X-Cache-Host
X-Nginx-Cache
X-Sorting-Hat-ShopId
Accept-Language
X-GeoCode
X-Detected-As
X-Worker
X-Generated-By
X-Lagoon
X-Optimistic-Header
CDN-RequestId
X-Vercel-Cache
X-Vercel-Id
X-Rocket-Nginx-Serving-Static
Azure-InstanceId
Azure-SlotName
Azure-SiteName
Azure-Version
Azure-RegionName
Source
X-B3-Traceid
Node
X-Fastly-Request-Id
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
X-Request-URI
CDN-Cache
CDN-RequestPullCode
CDN-CachedAt
CDN-RequestPullSuccess
LB
CDN-Uid
X-WP-CF-Super-Cache-Cookies-Bypass
X-Pass-Why
Protected
AMP-Access-Control-Allow-Source-Origin
Cross-Origin-Embedder-Policy
Fastcgi-Useragent
X-Vcl-Version
X-Tumblr-Pixel-3
X-App-Version
Alternate-Protocol
X-XRDS-Location
X-GEO
Expiry
X-Connection-Hash
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Ratelimit-Reset
X-ECache
X-Cache-Server
X-Aspnetmvc-Version
DB-Nickname
Onion-Location
X-Jobs
X-TA-CDN-Provider
X-Cache-Expired-At
X-Server-W
Sid
CF-IPCountry
X-PHP-Backend
Environment
X-Original-Request-Id
X-Fastcgi-Cache
Priority
Uber-Trace-Id
X-Response-Served-From
X-Api-Version
X-Proxy-Cache-Status
X-LSADC-Cache
X-Cache-Action
User-Cache-Control
X-Cluster-Node
X-Uri
X-MP-GENERATED-AT
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-TT-LOGID
X-LiteSpeed-Cache-Control
X-Mg-Request-UUID
HostName
X-Tx-Id
X-Nf-Request-Id
X-FB-TRIP-ID
WP-Super-Cache
Surrogated-Key
X-Platform
T-Server
X-Forwarded-Site
Vix-Hermes-Req-Id
X-Level-Front-Cache
X-Jungle-Id
A
X-Epic-Correlation-Id
X-A-Ccd
X-VTEX-Cache-Time
X-A-Dam
X-A-Dcw
X-Dispatcher-Server
X-A-Dgt
X-Ec-Fail
Wxu-Next-Region
Sslversion
X-Powered-By-VTEX-Cache
X-Proto
X-Ec-GeoHdr
Wxu-Next-Hostname
Wxu-Next-Commit
X-Esi-Check
Cache-Tv-Group
Magicmarker
Lang
Fusion-Component-Id
X-NMSegId
X-Node-Id
MD5-Digest
Edge-Cache
Fusion-Content-Id
Fusion-Content-Source
X-NCache
X-ND-Cache
Gannett-Cam-Experience-Id
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
Meta-Geo-Continent
DCR-Processing-Time-Ms
X-FC-Vary-Parameters
X-Origin-Expires
X-Org
Candidate-Md5Url
Rendered-Blocks
Req-ID
X-A-Wwc
Origin-Agent-Cluster
X-Op-Id-All
X-Mvc-Supplant-Cachable
DCR-Decision-By
Ngx.Var.Host
Content-Secure-Policy
Origin
NM-Fastcgi-Cache
Server-Host
X-A
X-UA-Device-Type
X-TIM-N
X-Block-Status
X-Content-Age
X-Gzip
X-Thanos
X-Test
X-SRCache-Key
X-Bc-Bl
X-Aed
X-Bip
X-Bl-Debug
X-Cache-Id
X-Conf
X-Vtex-Remote-Cache
X-Vdms-Version
X-Generated-On
X-Viewer-Country
X-VTEX-Cache-Server
X-Vdms-Path
X-GeoIP
X-Cache-NE
X-DC
X-Clientip
X-Varnish-Hostname
X-GeoIP-City
X-Gen-Mode
X-BCube-Filmed-By
X-Rojux
X-Ig-Origin-Region
X-SB
X-Hnp-Log
X-ScT
X-Developer
X-Device-Os
X-D
X-Request-Start
X-URL
X-Origin-Response-Time
X-NGINX-Cache
X-Cache-TTL-Remaining
X-GeoIP-Region-Code
X-Mvc-Supplant-OutputCached
X-From
Host-ID
We-Hiring
X-AK-Request-ID
X-Cache-Info
X-GeoIP-Country-Code
X-CGP
L5d-Success-Class
X-Geo-Header
X-Cache-Bucket
X-Amz-Storage-Class
X-Cdn-Srv
X-ApacheServer
Mail-Subject
X-HS-Content-Campaign-Id
X-Edge-Server
Ssr
X-Fastly-Cache
X-CUA
Sever-Int
X-Loc
X-Backend-Instance
X-HN
X-Fmm-Version
X-Core-Value
X-Auth-Group-Type
HA-Ipaddr
X-Auto-Login
Server-Hostname
Server-Ext
Origin-EX
PFcat
X-App-Name
X-Debug-Cache-Store
Origin-CC
Powered-By
Release
X-Eu-Site
X-Gdpr
W
X-Debug-Cache-Fetch
X-Csrf-Jwt
CDCHOST
X-Var-Ttl
C-Via
X-V-Cache
X-Newrelic-Synthetics
X-Origin-Time
X-Varnish-Director
X-Varnishpool
X-VG-WebCache
X-Via-Fastly
Cdn-Host
Canary
Cache-Provider
AKAMAI
X-PAYTM-SRV-ID
X-Region-Sid
X-Scheme
X-Render-Time
X-Request-Time
Ha-Gx-Prefs
X-RateLimit-Remaining-Second
X-Zone
X-Service
X-PERF
X-SD-PageType
X-RateLimit-Limit-Second
X-WA-Info
X-VarnishDD-TTL
X-Tt-Logid
X-Policy
Content-Style-Type
Content-Script-Type
X-Pubstack
DSUID
X-Nginx-Cache-Key
Fastly-SSL
Fastly-Backend-Name
Esi-Enabled
Yak-Timeinfo
X-Nyt-Route
XM
Cdncip
Cdnsip
Cdn-Request-Time
X-Wikidot-Backend
X-Hash
X-Server-IP
X-Section
X-Ig-Push-State
X-Human
X-Fastly-Backend
X-Aicache-OS
X-Varnish-Beresp-Ttl
X-Ec-Custom-Error
X-Varnish-Beresp-Status
X-Contensis-Viewer-Groups
X-DPWN-IS-SECURE
X-Wikidot-Static-Cache
X-Request-Host
X-VG-TLSProxy
X-Cache-Backend
X-GoCache-CacheStatus
X-CacheTTL
X-Dc
Gh-Request-Id
X-Cache-Aspx
X-We-Are-Hiring
X-Sn-Servicetimems
X-Varnish-Authentication
X-BBC-Edge-Cache-Status
X-SVT-ORM-RULES
X-Tb-Optimization-Total-Bytes-Saved
X-SVT-ORM-VERSION
X-B3-Trace-ID
X-Access
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Adler-Geo
True-Client-Country-4JS
Tube-Get-Contents
Click-Count-Error
Click-Count-Action-Start
Apple-News-Services-Request-Url
Cache-Key
Req-Svc-Chain
Pramga
Redirect-Candidate
X-Men
X-Ad-Load-Variation
X-Location
X-Micro-Cache
Platform
Producers
Tube-Got-Eval
Web-Mar-Region
Tube-Got-Results
X-Proxied-Request
X-Req
Fastly-GeoIP-CountryCode
Machine
Is-Eu
Country-Code
Tube-Return
Cluster
On-Server
V-Age
X-Mly-Id
X-Pool
L
X-AIR-PT
X-Date
Odigeo-Trace-Id
NGX
RNT-Machine
X-Accel-Expires-Debug
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Proxy-Firewall
X-Up
Cdn-Requestid
X-Acquia-Purge-Cdn-Unconfigured
RNT-Time
Datacenter
X-COUNTRY
X-Custom-Header
X-NodeID
Debug
X-Varnish-Hits
X-Ismobilevalue
X-Nananana
X-LB-ID
X-Akamai-Transformed
X-ID
Locid
X-Cs
X-CACHE-GROUP
X-Refresh
X-Pad
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-DefElseHash
X-DefHash
X-Varnish-CookieINHashed-On
X-Amz-Meta-Cb-Modifiedtime
X-Client-Ip
X-Platform-Router
X-LiteSpeed-Tag
CloudFront-Viewer-Country
X-Platform-Processor
X-Platform-Cluster
SID
Fastly-Drupal-HTML
X-Via-Popn
X-HA-Backend
X-Via-Popv
Pics-Label
X-Via-Poph
X-M-Log
X-Depends
X-VHOST
X-Servedbyhost
X-M-Reqid
Mime-Version
Ngx-Var-Key
X-Cached-By
GeoIP-Latitude
X-Old-Content-Length
X-Datadome
X-VC-TTL
X-Cache-FS-Status
X-Parent-Response-Time
X-Moov-Xdn-Version
Fastly-Drupal-Html
X-CS
X-CACHE-AGE
X-B3-Parentspanid
X-TH-Server
X-Moov-T
X-CDN-Cache-Status
X-LB-NoCache
Cross-Origin-Embedder-Policy-Report-Only
X-TIME
X-DynaTrace-JS-Agent
GeoIp-Country-Code
Resin-Trace
Cf-Ipcountry
Server-Info
X-Nc
NtCoent-Length
Server-ID
X-Presslabs-Stats
Cdn
X-B-Cookie
X-External-Request-Id
X-Application
X-Destination
BehaviorPad-Version
X-VCache
Uri
X-Wa
Cf-Device-Type
X-User
X-S-Cookie
X-Vgn-Hpd-Reason
X-Litespeed-Tag
X-Zen-Fury
X-ZONE
FSS-Cache
X-IAuth-Set-Uid
X-NewRelic-App-Data
True-Client-IP
X-APP
X-Flags
X-Providence-Cookie
X-Route-Name
X-Aspnet-Duration-Ms
CDN
X-Is-Crawler
X-Varnish-Beresp-TTL
X-Instance-Name
X-Sigma-Backend
X-Fpc
X-Cache-Date
X-Esi
X-Sigma
X-Rocket-Build-Number
X-HostName
X-TX-ID
X-API-Version
X-VServer
X-Srv
True-Client-Ip
X-DynaTrace
Srv
X-Vc
X-Content-Length
Tcn
X-HITS
X-Segment-20210421
X-Dynatrace-Js-Agent
Load-Balancing
X-Branch-Name
X-Oracle-DMS-ECID
X-Page-View
S-Rt
X-HOST
X-FPC
Serverhost
X-B3-Spanid
GeoIP-Country-Code
X-Cdn-Forward
X-APP-VERSION
Ohc-File-Size
Request-ID
X-WA
X-Dispatch
X-Cdn-Cache-Status
X-Dispatcher-Number
Hostname
X-DataCenter
X-NC
Type
Product
Vc-Max-Age
Server-Id
X-RequestId
X-Sql-Duration-Ms
X-Http-Reason
X-Sql-Count
X-Lb-Nocache
X-Webkit-Csp-Report-Only
X-Irp-Debug
X-FL-QIT-DEBUG
Geoip-Latitude
Srvid
Cl-Cache
ServerName
X-Geo
X-Ckpd-Fst-Backend
X-ServedByHost
X-Bug-Bounty
X-Via-CDN
X-SIPLIST1
IsBot
X-Via-SSL
X-Via-Edge
X-Owner
X-CSRF-TOKEN
DataCenter
WZWS-RAY
Edge-Copy-Time
X-VCL-Version
MIME-Version
Epwk-X-Cache
PICS-Label
X-Cst
Cloudfront-Viewer-Country
X-Via-PopN
X-Proxy-CacheRZ
Cross-Origin-Opener-Policy-Report-Only
X-CACHE-KEY
X-Via-PopV
XkeyRZ
X-Via-PopH
X-Core-Mission
Ohc-Cache-HIT
CacheControlHeader
X-Ha-Backend
Origin-Trial
X-Hit
X-Cache-Ttl
X-Qloud-Router
X-App
ServerHost
N-Cache
CountryCode
X-Correlation-ID
X-Ua
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Rtss
X-Amz-Meta-Opti
X-MSEdge-Features
X-MiniProfiler-Ids
X-MSEdge-Flight
X-Lb-Id
X-Fastly-Country-Code
Lb
X-Sqd-Ctime
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Sqd-Stime
X-Acquia-Application-Trace
Warning
X-Datacenter
X-Service-Response-Time
Sm-Log-Id
X-Web-Server
X-LAGOON
X-Forwarded-Path
X-Amz-Meta-Sha256
X-Amz-Meta-S3b-Last-Modified
X-Udemy-Cache-App-Namespace
X-IN-APIGATEWAY
X-Akamai-Device-Characteristics
X-Limited
X-Vmg-Version
User-Agent
Cneonction
X-Proxy-Cache-La3
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-Cdn-Request-ID
X-Check-Cacheable
X-Shop-Environment
X-Serial
Expect-Staple
X-RAMCache
Akamai-Cache-Status
X-Orig-Expires
X-Akamai-Pragma-Client-IP
X-Th-Server
X-Ramcache
X-Cache-Type
X-Requestid
X-CF-Lambda-Fn
Xkey-La3
Xkeylog
X-Snapshot-Date
X-Tenant
Ngx
X-CF-Lambda-Version