Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
X-XSS-Protection
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Xss-Protection
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
P3p
Content-Security-Policy-Report-Only
X-Runtime
X-AspNet-Version
X-DNS-Prefetch-Control
X-Cache-Status
Accept-CH
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Request-ID
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
X-Robots-Tag
Request-Context
X-Server
Keep-Alive
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Vhost
X-Proxy-Cache
X-Rq
X-Age
Xkey
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
X-Dns-Prefetch-Control
Cf-Apo-Via
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-CST
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
Accept-Ch-Lifetime
X-Server-Id
X-Readtime
X-Host
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
Accept-Ch
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Ruxit-JS-Agent
X-Trace
X-Litespeed-Cache
Content-Location
X-Url
X-Cache-Lookup
Service-Worker-Allowed
X-Oneagent-Js-Injection
X-Content-Type
X-Country
X-Clacks-Overhead
X-Edge
X-ECACHE
X-Mod-Pagespeed
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Midtier
X-Origin-Cache-Key
Cross-Origin-Opener-Policy
Cache-Tag
X-FTR-Request-ID
X-MS-InvokeApp
X-Mcache
X-Upstream
X-Powered-By-Plesk
X-TtlSet
X-Vname
X-ESI
X-PC
Nginx-Cache
Rating
Edge-Control
X-D2id
X-Kinja-Server
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Exp-Id
X-Element-Page-Cache
X-Cdn-Fetch
X-Browser-Type
Verso
X-Times
X-Ac
X-Server-Name
X-Cnection
SPIisLatency
SPRequestDuration
X-Ruxit-Js-Agent
X-Vcap-Request-Id
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-SID
X-Navigation-Version
X-Abt-Application-Version
X-RateLimit-Remaining
SPRequestGuid
X-SharePointHealthScore
X-Dw-Request-Base-Id
X-VARITI-CCR
X-GitHub-Request-Id
X-NF-Request-ID
X-Ser
X-B3-TraceId
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Origin-Trial
AR-CACHE
X-Cache-Key
S
RTSS
X-Server-ID
X-Mg-S
X-Ttl
X-Cache-TTL
Edge-Cache-Tag
X-Goog-Hash
X-Sol
X-Middleton-Display
Pagespeed
Display
X-Amz-Rid
X-Content-Security-Policy-Report-Only
Fastly-Restarts
X-Amzn-Trace-Id
X-Powered-CMS
X-Client-IP
X-NWS-LOG-UUID
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Kinsta-Cache
X-Version
X-Edge-Location-Klb
Access-Control-Request-Method
X-ARC
X-Varnish-TTL
Cache-Status
X-Recruiting
X-Webkit-Csp
X-Content-Digest
Arr-Disable-Session-Affinity
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-T
X-MSEdge-Ref
X-Forwarded-For
X-Ua-Device
Response
X-Middleton-Response
X-TraceId
Content-MD5
MicrosoftSharePointTeamServices
X-Accel-Expires
X-Hits
TP-Cache
X-Shield-Request-Id
X-Cached
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-RateLimit-Limit
Public-Key-Pins
X-Frontend
Server-Node
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Cache-Status
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-FTR-Expires
X-HS-Cache-Config
X-Id
X-Ua-Browser
X-Request-Processing-Time
MS-Author-Via
Payment
X-WebKit-CSP-Report-Only
X-Request-Received
X-DIS-Request-ID
X-Kinja-CCPA
X-ORACLE-DMS-RID
X-FastCGI-Cache
X-GUploader-UploadID
X-Forwarded-Proto
Front-End-Https
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
Cross-Origin-Resource-Policy
X-LLID
Cache-Tags
X-Fastcgi-Cache
TP-L2-Cache
X-LB-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Protected-By
Realpath
X-Origin-Server
Count-Hit
X-PressLabs-Stats
X-Daa-Tunnel
X-Distributor
X-Microsite
X-Request-Handler-Origin-Region
X-ORACLE-DMS-ECID
X-Page-Id
X-Cluster-Name
X-AppVersion
X-Activity-Id
X-Varnish-Backend
X-Az
MRF-Tech
Accept-Charset
X-F-Cache
X-B3-TraceId-Primal
Mrf-Cache-Status
X-NGENIX-Cache
X-Www-Served-By
X-Geo-Country
X-Correlation-Id
X-App-Server
X-FB-Debug
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Hostname
X-Goog-Metageneration
X-Debug-Info
X-Varnish-Server
Referer-Policy
Fastcgi-Cache
X-Envoy-Decorator-Operation
Host
X-TTL
X-Rid
Access-Control-Allow-Method
X-Git-Hash
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-RateLimit-Reset
Retry-After
Server-Name
DC
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Content-Options
X-Px
X-Load-Cache
X-B3-Sampled
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
X-Mobile
X-Contextid
Cleartype
TCN
X-Language
X-Origin-Cache
X-Revision
X-Trace-Id
X-Type
X-App-Environment
Paypal-Debug-Id
Charset
X-Grace
X-Fb-Rlafr
X-ASPNET-VERSION
X-Signature
X-B-Cache
X-Amz-Meta-S3cmd-Attrs
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-TT
X-Datadog-Parent-Id
X-XRDS-LOCATION
X-Cache-Control
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-CSRF-Token
Frame-Options
X-B
X-Amz-Replication-Status
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Logged-In
X-Ratelimit-Limit
Section-Io-Cache
Filterid
X-Seen-By
X-Upgrade-Enabled
X-Ezoic-Cdn
X-Whom
X-Wix-Request-Id
X-Fastly-Request-Id
X-Magnolia-Registration
X-Oracle-Dms-Ecid
X-Fastly-Request-ID
X-Varnish-Ttl
Healthy
X-Newrelic-App-Data
X-EdgeConnect-Cache-Status
X-Azure-Ref
Content-Disposition
X-App-Version
X-Node-Name
X-B3-Traceid
X-Proxy
Backend
Akamai-GRN
X-Oracle-Dms-Rid
X-N
X-Template
Upgrade-Insecure-Requests
X-Air-Pt
X-Proxy-Cache-Info
NGB
Refresh
X-Original-Request-Id
X-Response-Served-From
X-Rendered-As
X-Is-Bot
X-Servername
X-Unique-Id
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-ProcessESI
SD-X-WS
MS-CV
Url
X-Page-View
X-RemovedCookies
X-RTag
Ms-Operation-Id
X-Cacheable-TTL
X-Datadog-Sampled
X-Cache-Grace
Viewport
Liferay-Portal
X-Instance
X-Jobs
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-User-Agent
X-Region
X-L-Path
X-Amzn-Remapped-Content-Length
X-Environment-Context
X-Debug
X-FW-Dynamic
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
From-Origin
X-FW-Hash
X-FW-Serve
X-UUID
X-Varnish-Grace
X-FW-Version
X-FW-Static
X-FW-Server
X-Ratelimit-Remaining
X-FW-Type
X-Adobe-Content
X-B3-SpanId
Fastly-SIE
Country
X-Adobe-Loc
X-Cache-Hit
X-Device-Type
X-Debug-IsPreview
X-Debug-IsConnected
X-IPS-LoggedIn
Fastly-SWR
X-Use-Magma
X-NYM-Debug-Backend
X-Rule
X-Status
Surrogate-Key
X-Hosted-By
X-G
X-Backend-Name
X-WP-CF-Super-Cache
Amp-Access-Control-Allow-Source-Origin
X-Hl-Ver
X-WP-CF-Super-Cache-Cache-Control
X-Webkit-CSP
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
ServerID
X-Cache-Age
X-Content-Powered-By
Protected
X-XRDS-Location
X-Http-Reason
X-Cache-Status-Check
X-Akamai-Request-ID2
X-NODE
X-Origin-TTL
X-Origin-CC
Version
Alternate-Protocol
X-VC-Cache
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Time
X-HTML-Minification-Powered-By
Countrycode
X-Akamai-Edgescape
WPO-Cache-Status
WPO-Cache-Message
X-Framework
X-INCAP-ABP
X-Rocket-Nginx-Serving-Static
X-Via-JSL
Front
X-Nginx-Cache
X-Edge-Location
X-Source
GEO-INFO
X-CDN-Forward
X-Cache-Rule
CF-IPCountry
Access-Control-Request-Headers
SRV
CDN-RequestId
X-Httpd
X-Mode
X-Accel-Version
X-Storage
X-Endurance-Cache-Level
X-Tec-Api-Root
X-WP-CF-Super-Cache-Active
X-Tec-Api-Origin
X-Tec-Api-Version
X-Use-Mantle
X-UPSTREAM-Address
X-Upstream-Ht
X-VC
Webserver
Meta-Geo
Filters
X-Cache-Operation
X-Upstream-Ct
X-Rewrite-Enabled
X-Xfnlog-Site
X-Rn-Rsrv
OT-Force-Account-Verify
Accept-Language
X-JoinUs
Xet-Cookie
X-Loop
Selected-Fe
X-Lambda-Id
X-Tumblr-Pixel-3
X-Varnish-Age
X-Timing-Wait
X-Real-IP
X-Served-From
X-Tumblr-Pixel-2
X-Detected-As
X-SaId
X-Proxy-Build
X-Director
X-Soup
X-Tncms
X-BYPASS-REASON
X-ProxyCache-Key
X-Skip-Cache
X-ProxyCache-Status
X-Sql-Duration-Ms
X-Cache-Debug
ServedBy
X-Handled-By
X-Say-TTL
X-Say-Cacheable
Apigw-Requestid
X-Cms-Context
X-Cache-Time
X-Redis-Cache
X-Sql-Count
X-SayCDN-TTL
X-Varnish-Beresp-Grace
X-Origin-Hint
Property-Id
Webcakes-App-Version
X-Format
X-Varnish-Cache-Hits
TWC-Device-Class
Webcakes-App-Name
X-Cache-Host
Azure-InstanceId
Azure-RegionName
DB-Nickname
X-GeoCountry
X-GeoCode
X-Vcache
X-Server-W
Azure-SiteName
Azure-SlotName
Azure-Version
X-No-Session
TWC-Connection-Speed
Webcakes-Region
X-RM-Cache-TTL
Web-Mar-Node
Xserver
TWC-Privacy
X-Adobe-Source
TWC-GeoIP-LatLong
X-COUNTRY
X-Uri
X-Logging-Id
X-Restarts
X-Worker
TWC-Locale-Group
TWC-GeoIP-Country
Mn-Server-Ip
X-Generation-Time
X-Extlb
X-AWS-Id
X-DynaTrace
X-Fetched-On
X-Cache-Server
X-Forwarded-Host
X-Container-Uri
X-Proxied
X-VCT
X-RCS-CacheZone
X-Labrador-Cache-Channel
X-LJ-Flow-ID
X-Vercel-Cache
X-Routing-Service
X-Vercel-Id
X-VWS-Id
X-Tb
X-Git-Commit
X-PHP-Host
X-IPLB-Instance
X-Zipkin-Id
X-IPLB-Request-ID
X-Browser-Name
X-Cluster
X-ServerID
X-Tcp-Rtt
X-Reqid
X-AB
X-Is-Mobile
X-Is-Desktop
X-Frame-Option
Cache-Tv-Group
X-Is-Tablet
X-Is-Supported-Browser
X-Geo-Region
X-Origin
X-Provided-By
X-Ms-Version
X-S
X-Ms-Request-Id
X-R9-Blue-Green-Version
X-FB-TRIP-ID
Section-Io-Id
X-Locale
X-Site-Version
Node
Content-Secure-Policy
Priority
X-Platform-Cluster
X-Platform-Router
X-Platform-Processor
AMP-Access-Control-Allow-Source-Origin
Fastcgi-Useragent
X-MP-GENERATED-AT
X-Webstats-RespID
Source
WZWS-RAY
X-Web-Node
X-Drupal-Cache-Tags
X-Vcl-Version
Onion-Location
S-Rt
WP-Super-Cache
X-Drupal-Cache-Contexts
X-Origin-Date
Cross-Origin-Embedder-Policy
X-Ua
X-Content-Age
CDN-Uid
X-Storefront-Renderer-Rendered
CDN-PullZone
CDN-CachedAt
CDN-Cache
X-Shopify-Stage
CDN-EdgeStorageId
CDN-RequestPullSuccess
X-Alternate-Cache-Key
CDN-RequestPullCode
CDN-RequestCountryCode
Locale
X-Generated-By
X-Urbn-Context-Path
X-Xrds-Location
X-Urbn-Site-Id
X-SRV
X-ShopId
X-Sorting-Hat-PodId
X-Cluster-Node
X-Cache-Action
X-Sorting-Hat-ShopId
X-ShardId
X-Sucuri-Cache
X-Cdn-Origin
X-Buckets
Sid
X-Proxy-Cache-Status
X-Sucuri-ID
X-Mg-Request-UUID
X-Pass-Why
X-Varnish-Beresp-Ttl
X-Newrelic-Synthetics
X-TT-LOGID
Cross-Origin-Window-Policy
X-DataDome
X-Cache-Expired-At
Fastly-Drupal-HTML
Thinkindot-CacheControl-Type
X-CMSURLCustom
X-Shield-Cache-Expires
X-Thinkindot-L3
Cache
Thinkindot-Control
X-Scope-Id
Thinkindot-CacheControl
TDXMobile
X-Request-URI
Cross-Origin-Embedder-Policy-Report-Only
X-LSADC-Cache
X-GEO
X-Aspnetmvc-Version
X-Bc-Bl
X-BCube-Filmed-By
X-A-Ccd
Ngx-Var-Key
Meta-Geo-Continent
Ngx.Var.Host
Origin
Redirect-Candidate
Origin-Agent-Cluster
MD5-Digest
Lang
DCR-Processing-Time-Ms
DCR-Decision-By
Gannett-Cam-Experience-Id
CDCHOST
Candidate-Md5Url
Rendered-Blocks
Sslversion
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Aed
X-Application
X-A-Dam
X-Bl-Debug
T-Server
Surrogated-Key
Type
V-Age
X-A
X-B-Cookie
X-D
X-Epic-Correlation-Id
X-External-Request-Id
X-Ec-GeoHdr
X-Ec-Fail
X-Cache-Bucket
X-PAYTM-SRV-ID
X-TIM-N
X-Viewer-Country
X-Correlation-ID
X-Vdms-Version
X-Vdms-Path
X-Ec-Custom-Error
X-Developer
X-ScT
X-Rojux
X-S-Cookie
X-Conf
X-Scheme
X-VCache
X-Destination
X-Vtex-Remote-Cache
X-SRCache-Key
X-Cache-NE
X-Service
X-Datadome
X-TA-CDN-Provider
X-Via-CDN
HostName
Edge-Copy-Time
X-TimeS
X-Via-Edge
X-Optimistic-Header
X-Via-SSL
Fastly-GeoIP-CountryCode
X-SVT-ORM-RULES
Fastly-SSL
X-Sigma-Backend
X-We-Are-Hiring
X-SD-PageType
X-Server-IP
X-Section
Server-Hostname
Environment
X-Sigma
Server-Ext
X-Varnish-Director
X-Varnish-Beresp-Status
Magicmarker
Host-ID
X-VG-WebCache
X-V-Cache
X-Up
L
X-SVT-ORM-VERSION
X-Thanos
Release
Pramga
X-VServer
X-Proxied-Request
X-GeoIP-Country-Code
X-Generated-On
X-Gdpr
X-GeoIP-Region-Code
X-Hash
X-Instance-Name
X-Human
X-Fastly-Cache
X-Fastly-Backend
X-Core-Mission
X-Cache-Info
Country-Code
X-Debug-Cache-Fetch
X-B3-Trace-ID
X-Debug-Cache-Store
X-Level-Front-Cache
X-Loc
X-Req
X-Pubstack
X-Request-Time
X-Rocket-Build-Number
X-SB
Ssr
X-Pool
X-Origin-Time
X-Men
X-Aicache-OS
X-Nyt-Route
X-Acquia-Purge-Cdn-Unconfigured
X-Op-Id-All
X-Access
Sever-Int
X-Bip
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
User-Cache-Control
X-Core-Value
X-Varnishpool
X-Clientip
X-Cache-Date
X-Block-Status
X-TH-Server
X-UA-Device-Type
X-Sn-Servicetimems
X-Node-Id
X-Var-Ttl
X-Dispatcher-Server
X-Device-Os
X-BBC-Edge-Cache-Status
Atl-Traceid
Uber-Trace-Id
Vix-Hermes-Req-Id
Tube-Return
Tube-Got-Results
Tube-Get-Contents
Tube-Got-Eval
We-Hiring
Web-Mar-Region
X-ApacheServer
X-Auto-Login
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Forwarded-Site
X-FC-Vary-Parameters
X-PERF
X-Platform
X-Origin-Response-Time
X-Org
X-NCache
X-Nginx-Cache-Key
X-Policy
X-RateLimit-Limit-Second
X-Varnish-Hostname
X-Slack-Backend
X-VG-TLSProxy
X-Request-Host
X-RateLimit-Remaining-Second
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Geo-Header
X-GeoIP
X-Zen-Fury
True-Client-Country-4JS
X-Gen-Mode
X-GeoIP-City
X-GoCache-CacheStatus
X-Irp-Debug
X-Mly-Id
X-WP-CF-Super-Cache-Cookies-Bypass
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Slack-Shared-Secret-Outcome
X-CacheTTL
Proxy-Firewall
Req-Svc-Chain
Canary
Gh-Request-Id
Machine
C-Via
On-Server
Click-Count-Error
Mail-Subject
Server-Host
Cache-Provider
DSUID
Click-Count-Action-Start
X-Parent-Response-Time
X-DC
X-HA-Backend
X-Cache-TTL-Remaining
X-Esi-Check
N-Cache
X-Cache-Id
X-Wikidot-Static-Cache
X-SIPLIST1
X-Cdn-Srv
Producers
X-Gzip
X-CF-Lambda-Fn
Req-ID
AKAMAI
LB
X-Request-Start
X-DPWN-IS-SECURE
NM-Fastcgi-Cache
X-ZONE
X-Date
Adler-Geo
X-CF-Lambda-Version
X-From
Platform
X-Fmm-Version
X-Wikidot-Backend
X-Tt-Logid
Expect-Staple
X-Via-Popv
X-Owner
X-Accel-Expires-Debug
X-Old-Content-Length
X-Via-Poph
X-NMSegId
X-Via-Popn
Is-Eu
X-Ad-Load-Variation
Esi-Enabled
X-App-Name
X-Proto
IsBot
X-WA-Info
X-Micro-Cache
X-Test
W
X-Edge-Server
X-Forwarded-Path
Cdn-Request-Time
X-Orig-Expires
X-Csrf-Jwt
Cdn-Host
Pics-Label
Xc-Version
Cluster
Ha-Gx-Prefs
Cf-Device-Type
X-Ah-Environment
X-Amz-Meta-Cb-Modifiedtime
Fastly-Backend-Name
L5d-Success-Class
X-Cache-Type
X-Dc
X-Qloud-Router
X-CGP
X-Eu-Site
HA-Ipaddr
X-Tenant
X-Shop-Environment
X-Connection-Hash
Datacenter
Expiry
X-Gamma-Serve
NGX
X-Branch-Name
X-Contensis-Viewer-Groups
Content-Style-Type
Content-Script-Type
X-Moov-Xdn-Version
X-Varnish-Authentication
X-Moov-T
X-Cache-Aspx
A
X-Tx-Id
Cmsid
Cmstype
X-NGINX-Cache
RNT-Machine
X-LB-NoCache
RNT-Time
Locid
Cache-Key
SID
Cdn
X-Ratelimit-Reset
X-Region-Sid
X-LB-ID
X-Nc
X-Vmg-Version
Cdncip
Yak-Timeinfo
X-Varnish-Hits
X-Servedbyhost
X-AK-Request-ID
X-ND-Cache
Server-ID
X-Refresh
CPC-Age
Cdnsip
CPC-Cache
X-Wa
X-Cdn-Diag
X-Nf-Request-Id
X-VHOST
X-Api-Version
NtCoent-Length
X-MCACHE
X-VarnishDD-TTL
RATING
X-Client-Ip
X-HN
GeoIp-Country-Code
X-LAGOON
PFcat
X-Amz-Storage-Class
X-Tb-Optimization-Total-Bytes-Saved
X-CDN-Cache-Status
Cdn-Requestid
X-TIME
X-Backend-Instance
X-DynaTrace-JS-Agent
X-Fpc
X-Srv
CloudFront-Viewer-Country
XM
CacheControlHeader
X-Azure-Ref-OriginShield
X-B3-Parentspanid
X-Akamai-Transformed
Resin-Trace
X-Via-Fastly
X-TX-ID
X-Variation
X-API-Version
X-Nananana
X-Origin-Expires
X-Cache-Backend
X-Hit
X-LiteSpeed-Tag
X-CACHE-AGE
Uri
User-Agent
X-Lagoon
X-LiteSpeed-Cache-Control
X-Zone
VNS-Age
X-URL
MIME-Version
X-Proxy-CacheRZ
X-CSRF-TOKEN
XkeyRZ
VNS-Cache
Cache-Name
Cross-Origin-Opener-Policy-Report-Only
X-Amz-Meta-Opti
X-Info
X-NewRelic-App-Data
X-Fastly-Country-Code
Hostname
Tcn
X-ECache
X-B3-Spanid
True-Client-Ip
Lb
X-Datacenter
True-Client-IP
X-Vc
X-DataCenter
X-Dynatrace-Js-Agent
DataCenter
X-HostName
GeoIP-Latitude
X-Geo
X-Dispatcher-Number
X-UA
X-Location
X-Ig-Origin-Region
X-Cached-By
Mime-Version
Fastly-Drupal-Html
Cache-Hits
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-NWS-UUID-VERIFY
Fusion-Deployment-Id
Fusion-Source
X-Mid
X-AIR-PT
Powered-By
Cf-Ipcountry
X-Presslabs-Stats
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-IAuth-Set-Uid
BehaviorPad-Version
X-Varnish-Beresp-TTL
X-Jungle-Id
X-Cloudmap
X-CUA
Origin-CC
X-CS
Origin-EX
Srv
X-User
X-Traceid
CountryCode
Debug
X-Esi
X-FPC
Ohc-File-Size
GeoIP-Country-Code
X-Segment-20210421
X-Dispatch
X-Cache-Enabled
CDN
Server-Info
X-Wp-Cf-Super-Cache-Cache-Control
Server-Id
Location
X-Lb-Id
X-Oracle-DMS-ECID
X-Cdn-Cache-Status
X-Wp-Cf-Super-Cache
X-RID
Cl-Cache
X-Render-Time
My-App
Wpo-Cache-Message
Ohc-Cache-HIT
Wpo-Cache-Status
X-NC
CF-Ctrl
X-Wormhole-Sdk
X-WA
X-ServedByHost
X-Litespeed-Tag
X-Snapshot-Date
X-Internal-Host
YJS-ID
X-Cs
Load-Balancing
X-Nitro-Cache
X-App
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-MSEdge-Features
X-MSEdge-Flight
X-Fastly-Backend-Reqs
Edge-Cache
X-Auth-Group-Type
X-Lb-Nocache
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Powered-By-VTEX-Cache
Ms-Author-Via
X-Litespeed-Cache-Control
X-VCL-Version
X-ID
Xkey-La3
X-Proxy-Cache-La3
Xkeylog
X-Cdn-Request-ID
X-Nitro-Cache-From
X-Nitro-Rev
CF-Cached-On
X-Cache-FS-Status
X-Akamai-Pragma-Client-IP
X-MiniProfiler-Ids
X-Dw-Trace-Id
OriginIP
X-Via-PopV
X-Via-PopH
X-Acquia-Site
X-IN-APIGATEWAY
Memcached
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
Time
Memory
X-IN-APIGATEWAYSSL
X-Via-PopN
X-Ha-Backend
X-FL-QIT-DEBUG
Srvid
X-Ig-Push-State
FSS-Cache
Ngx
X-FL-EDGE
X-Th-Server
X-APP-VERSION
X-Shardid
X-Sorting-Hat-Podid
X-Shopid
X-Cache-Version
X-Sorting-Hat-Shopid
Odigeo-Trace-Id
X-NodeID
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Mg-Cache
X-Varnish-Remaining-TTL
X-Vary
Akamai-Cache-Status
X-Service-Response-Time
X-RequestId
X-Udemy-Cache-App-Namespace
X-DefElseHash
X-Te-Duration-Ms
Geoip-Latitude
X-Pad
X-Sucuri-Id
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Http-Duration-Ms
X-Http-Count
X-Check-Cacheable
X-Serial
X-Te-Count
Sm-Log-Id
X-Fastly-Cache-Hits
X-DefHash
Yjs-Id
X-Lsadc-Cache
X-Web-Server