Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-XSS-Protection
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-Ua-Compatible
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-UA-Device
X-Cache-Group
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
X-Age
Permissions-Policy
X-Vhost
X-Amz-Version-Id
Allow
X-Dns-Prefetch-Control
X-Dispatcher
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Host
X-Server-Id
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
X-Litespeed-Cache
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Application-Context
X-Ruxit-JS-Agent
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-CST
X-NWS-LOG-UUID
X-Country
Service-Worker-Allowed
X-Country-Code
X-Url
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Oneagent-Js-Injection
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Times
X-Server-Name
X-FTR-Request-ID
X-Vname
X-PC
X-TtlSet
X-Daa-Tunnel
X-Webkit-Csp
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-ESI
X-Cnection
X-Upstream
Edge-Control
X-GitHub-Request-Id
X-MS-InvokeApp
X-D2id
X-Element-Page-Cache
X-Ac
Verso
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Aws-Lambda-Call-Status
X-GoogleNews-Bot
X-Exp-Variant
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
X-ECACHE
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Ser
X-Vcap-Request-Id
X-Navigation-Version
X-Cache-TTL
X-B3-TraceId
X-Mod-Pagespeed
X-Abt-Application-Version
SPIisLatency
SPRequestDuration
X-Ruxit-Js-Agent
AR-CACHE
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
Fastly-Restarts
X-NF-Request-ID
X-Client-IP
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Display
X-Sol
X-Middleton-Display
Pagespeed
X-RateLimit-Remaining
Edge-Cache-Tag
X-Mg-S
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Powered-CMS
X-Amzn-Trace-Id
X-Middleton-Response
Response
Cache-Status
X-VARITI-CCR
X-Cache-Key
Access-Control-Request-Method
X-Version
X-Goog-Hash
X-ARC
RTSS
X-Content-Digest
X-Fastly-Request-ID
X-TraceId
X-Forwarded-For
Cross-Origin-Resource-Policy
X-Recruiting
X-T
X-Varnish-TTL
X-Pinterest-Rid
Pinterest-Generated-By
Realpath
Pinterest-Version
X-Ttl
X-Correlation-Id
X-MSEdge-Ref
MS-Author-Via
Front-End-Https
X-Ratelimit-Limit
Fastcgi-Cache
X-Cached
Content-MD5
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Ua-Browser
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
Server-Node
X-FTR-Backend
Payment
X-Protected-By
X-FTR-Balancer
X-PDP-UNCACHING-HASH
X-Request-Processing-Time
Public-Key-Pins
Arr-Disable-Session-Affinity
X-Request-Received
X-LLID
X-Forwarded-Proto
MicrosoftSharePointTeamServices
X-Shield-Request-Id
X-Frontend
X-HS-Combine-CSS
TP-Cache
X-SRCache-Fetch-Status
X-Origin-Cache-Key
X-SRCache-Store-Status
X-Distributor
X-Accel-Expires
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-FTR-Expires
X-Server-ID
Count-Hit
X-GUploader-UploadID
X-Hits
X-Origin-Server
X-LB-Cache
X-ORACLE-DMS-RID
X-Ezoic-Cdn
X-Content-Security-Policy-Report-Only
X-Request-Handler-Origin-Region
X-Microsite
X-Activity-Id
X-AppVersion
X-Az
Host
X-PressLabs-Stats
X-Varnish-Backend
X-TEC-API-ORIGIN
X-Ua-Device
X-TEC-API-VERSION
X-TEC-API-ROOT
MRF-Tech
X-Cluster-Name
Mrf-Cache-Status
X-B3-TraceId-Primal
X-TTL
Retry-After
Cache-Tags
X-Ratelimit-Remaining
X-App-Server
X-Www-Served-By
X-Varnish-Server
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
X-Id
Server-Name
X-Hostname
X-Geo-Country
Cleartype
X-NODE
X-NGENIX-Cache
X-Envoy-Decorator-Operation
X-DIS-Request-ID
X-Newrelic-App-Data
Referer-Policy
X-Goog-Metageneration
X-Upgrade-Enabled
TP-L2-Cache
X-CSRF-Token
X-Seen-By
X-Oracle-Dms-Ecid
X-Git-Hash
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Azure-Ref
Access-Control-Allow-Method
X-RateLimit-Limit
TCN
X-Load-Cache
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-F-Cache
X-Tt-Trace-Host
X-Proxy
X-Unique-Id
X-Tt-Trace-Tag
X-Grace
X-ORACLE-DMS-ECID
Filterid
X-Revision
X-Debug-Info
X-Cache-Control
X-Px
Healthy
X-XRDS-LOCATION
Section-Io-Cache
X-Request-Guid
Paypal-Debug-Id
X-TT
X-Trace-Id
X-B
DC
X-FB-Debug
X-B3-Sampled
X-Type
X-Contextid
X-Page-Id
X-Fb-Rlafr
X-Oracle-Dms-Rid
X-N
X-Logged-In
X-Mobile
X-WP-CF-Super-Cache
Viewport
X-WP-CF-Super-Cache-Cache-Control
X-Varnish-Ttl
X-Debug
X-Whom
X-Template
Charset
Fastly-SIE
X-Language
Fastly-SWR
X-Goog-Stored-Content-Length
X-Time
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Goog-Generation
X-Goog-Storage-Class
X-Datadog-Parent-Id
X-Goog-Stored-Content-Encoding
X-Cache-Grace
X-Content-Options
X-Webkit-CSP
Version
X-Magnolia-Registration
X-Via-JSL
X-RateLimit-Reset
X-Wix-Request-Id
X-EdgeConnect-Cache-Status
Content-Disposition
X-App-Environment
X-Varnish-Grace
X-Signature
X-B-Cache
X-Node-Name
X-Origin-Cache
X-Amzn-Remapped-Content-Length
X-RemovedCookies
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-ProcessESI
X-Tumblr-Pixel
X-Datadog-Sampled
X-Debug-IsPreview
X-Tumblr-Pixel-0
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Rule
X-Tumblr-Pixel-1
X-Tumblr-User
X-Debug-IsConnected
SD-X-WS
X-G
MS-CV
Ms-Operation-Id
X-RTag
X-UUID
X-Amz-Replication-Status
X-Hl-Ver
X-Backend-Name
GEO-INFO
X-Storage
X-FW-Dynamic
X-FW-Type
X-FW-Hash
X-FW-Static
X-Adobe-Loc
X-FW-Server
X-FW-Version
X-FW-Serve
X-Adobe-Content
X-Instance
ServerID
X-Proxy-Cache-Info
X-Device-Type
SRV
X-User-Agent
X-Rendered-As
Liferay-Portal
X-Is-Bot
X-Cacheable-TTL
X-IPS-LoggedIn
X-NYM-Debug-Backend
X-Region
Country
X-Cache-Hit
X-B3-SpanId
X-Cache-Age
X-Status
X-Environment-Context
X-L-Path
NGB
X-Real-IP
X-Source
Countrycode
X-ServerID
X-Rid
X-NWS-UUID-VERIFY
Surrogate-Key
Akamai-GRN
X-Sucuri-Cache
X-Servername
X-Sucuri-ID
From-Origin
X-WP-CF-Super-Cache-Active
OT-Force-Account-Verify
X-VC-Cache
Cross-Origin-Window-Policy
X-UA
X-WebKit-CSP-Report-Only
X-RM-Cache-TTL
Backend
Upgrade-Insecure-Requests
Amp-Access-Control-Allow-Source-Origin
X-INCAP-ABP
Front
X-Framework
X-Mode
X-Xrds-Location
X-Air-Pt
Refresh
X-AB
Frame-Options
X-Cache-Time
X-Akamai-Request-ID2
X-Content-Powered-By
X-Buckets
X-HTML-Minification-Powered-By
X-DataDome
Xet-Cookie
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-RID
X-Handled-By
Url
X-Wormhole-Sdk
X-Endurance-Cache-Level
Webserver
X-VC
X-Edge-Location
X-No-Session
X-Reqid
X-Timing-Wait
X-Origin-Date
X-SaId
X-VWS-Id
X-Rn-Rsrv
X-Akamai-Edgescape
X-Cluster
X-AWS-Id
Selected-Fe
Meta-Geo
Filters
X-Rewrite-Enabled
X-Webstats-RespID
X-Azure-Ref-OriginShield
X-RCS-CacheZone
X-JoinUs
X-Proxy-Build
Access-Control-Request-Headers
X-Origin-TTL
X-UPSTREAM-Address
X-LJ-Flow-ID
X-Vcache
X-Origin-CC
Webcakes-App-Version
TWC-Connection-Speed
Webcakes-Region
TWC-Privacy
Property-Id
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Webcakes-App-Name
TWC-Locale-Group
X-Container-Uri
X-IPLB-Instance
X-IPLB-Request-ID
X-Cache-Rule
X-Cache-Operation
X-Git-Commit
Atl-Traceid
X-Labrador-Cache-Channel
X-Drupal-Cache-Tags
X-Fetched-On
X-Generation-Time
Mn-Server-Ip
X-Origin
X-R9-Blue-Green-Version
X-Provided-By
X-PHP-Host
X-Served-From
X-Xfnlog-Site
X-Tumblr-Pixel-2
X-VCT
X-Logging-Id
X-Origin-Hint
ServedBy
X-Ms-Request-Id
X-Ms-Version
X-SRV
Thinkindot-Control
X-Zipkin-Id
Web-Mar-Node
X-Tb
X-Thinkindot-L3
X-Httpd
X-Web-Node
X-Scope-Id
X-Site-Version
X-Drupal-Cache-Contexts
X-BYPASS-REASON
Thinkindot-CacheControl
TDXMobile
X-Shield-Cache-Expires
X-Cache-Debug
Cache
Section-Io-Id
Thinkindot-CacheControl-Type
X-CMSURLCustom
X-Cloudmap
X-Extlb
X-Hosted-By
X-Varnish-Cache-Hits
WPO-Cache-Message
WPO-Cache-Status
X-Redis-Cache
X-Restarts
X-Cache-Status-Check
X-Locale
X-Accel-Version
X-CDN-Forward
X-Adobe-Source
X-Proxied
X-ProxyCache-Status
X-Routing-Service
X-ProxyCache-Key
X-Director
X-Upstream-Ht
X-Varnish-Age
X-Cms-Context
X-Format
X-Cdn-Origin
X-Is-Tablet
X-Skip-Cache
X-Lambda-Id
X-Is-Supported-Browser
X-Soup
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-Tncms
X-Is-Desktop
X-S
X-Forwarded-Host
X-Loop
X-Upstream-Ct
X-Browser-Name
X-Frame-Option
X-Tcp-Rtt
X-Geo-Region
X-Is-Mobile
Apigw-Requestid
X-ShopId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-GeoCountry
X-GeoCode
Accept-Language
X-Nginx-Cache
X-Shopify-Stage
Xserver
X-Alternate-Cache-Key
X-Varnish-Beresp-Grace
X-Cache-Host
Cache-Hits
X-Detected-As
X-ShardId
X-Worker
X-Generated-By
X-Vercel-Cache
X-Lagoon
X-Vercel-Id
X-Rocket-Nginx-Serving-Static
CDN-RequestId
X-Optimistic-Header
Azure-RegionName
Azure-SlotName
Azure-SiteName
Azure-Version
Azure-InstanceId
Node
X-B3-Traceid
Source
X-Fastly-Request-Id
CDN-PullZone
CDN-RequestCountryCode
X-Request-URI
X-WP-CF-Super-Cache-Cookies-Bypass
CDN-RequestPullCode
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestPullSuccess
CDN-Uid
Protected
LB
Fastcgi-Useragent
Cross-Origin-Embedder-Policy
X-Pass-Why
AMP-Access-Control-Allow-Source-Origin
X-Vcl-Version
X-Tumblr-Pixel-3
Alternate-Protocol
X-XRDS-Location
X-GEO
X-App-Version
X-Connection-Hash
X-Tec-Api-Origin
X-Tec-Api-Version
Expiry
X-Tec-Api-Root
X-Ratelimit-Reset
X-ECache
X-Cache-Server
X-TA-CDN-Provider
X-Jobs
Onion-Location
DB-Nickname
X-Cache-Expired-At
X-Server-W
Sid
CF-IPCountry
Environment
X-PHP-Backend
X-Api-Version
X-Original-Request-Id
X-Response-Served-From
X-Fastcgi-Cache
Uber-Trace-Id
Priority
X-Proxy-Cache-Status
X-LSADC-Cache
User-Cache-Control
X-Cache-Action
X-Cluster-Node
HostName
X-Uri
X-MP-GENERATED-AT
Locale
X-TT-LOGID
X-LiteSpeed-Cache-Control
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Mg-Request-UUID
X-Tx-Id
X-Nf-Request-Id
X-FB-TRIP-ID
WP-Super-Cache
T-Server
X-Jungle-Id
X-A-Ccd
X-Ig-Origin-Region
X-A-Dam
X-A-Dgt
Surrogated-Key
X-Origin-Expires
A
X-Dispatcher-Server
X-Forwarded-Site
X-A-Dcw
Vix-Hermes-Req-Id
X-Proto
X-Ec-GeoHdr
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Powered-By-VTEX-Cache
Sslversion
X-Platform
X-Viewer-Country
X-Esi-Check
X-Epic-Correlation-Id
X-Ec-Fail
Server-Host
Magicmarker
Lang
Fusion-Component-Id
X-NMSegId
MD5-Digest
DCR-Processing-Time-Ms
Meta-Geo-Continent
Fusion-Content-Id
Fusion-Content-Source
X-ND-Cache
X-NCache
Gannett-Cam-Experience-Id
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
DCR-Decision-By
X-Node-Id
X-FC-Vary-Parameters
Rendered-Blocks
Candidate-Md5Url
Req-ID
X-A-Wwc
Cache-Tv-Group
X-Org
X-Op-Id-All
Ngx.Var.Host
X-Mvc-Supplant-Cachable
Content-Secure-Policy
NM-Fastcgi-Cache
Origin-Agent-Cluster
Origin
X-Level-Front-Cache
X-A
X-Bc-Bl
X-DC
X-BCube-Filmed-By
X-SRCache-Key
X-Cache-NE
X-Gen-Mode
X-GeoIP
X-Varnish-Hostname
X-Content-Age
X-Vtex-Remote-Cache
X-Conf
X-Bip
X-Thanos
X-TIM-N
X-UA-Device-Type
X-Gzip
X-Test
X-Block-Status
X-Aed
X-Bl-Debug
X-Cache-Id
X-D
X-GeoIP-City
X-SB
X-Generated-On
X-Developer
X-Vdms-Version
X-Rojux
X-VTEX-Cache-Server
X-Clientip
X-Request-Start
X-Device-Os
X-Vdms-Path
X-VTEX-Cache-Time
X-ScT
X-Hnp-Log
X-URL
X-Origin-Response-Time
X-NGINX-Cache
L5d-Success-Class
X-GeoIP-Country-Code
Origin-CC
Origin-EX
X-Mvc-Supplant-OutputCached
Mail-Subject
Host-ID
X-Geo-Header
X-Cdn-Srv
X-Cache-TTL-Remaining
X-GeoIP-Region-Code
X-Cache-Info
X-CGP
X-Cache-Bucket
Server-Hostname
W
X-Edge-Server
X-Debug-Cache-Fetch
X-Gdpr
X-CUA
X-Eu-Site
X-Debug-Cache-Store
We-Hiring
X-Amz-Storage-Class
X-AK-Request-ID
X-ApacheServer
X-HS-Content-Campaign-Id
X-App-Name
X-From
X-Csrf-Jwt
X-Fastly-Cache
Sever-Int
Ssr
Server-Ext
X-Loc
Powered-By
Release
X-Backend-Instance
X-HN
X-Core-Value
HA-Ipaddr
X-Auth-Group-Type
X-Fmm-Version
X-Auto-Login
PFcat
CDCHOST
X-Zone
C-Via
X-Request-Time
AKAMAI
X-Origin-Time
X-Scheme
Cache-Provider
X-WA-Info
Cdncip
Cdn-Request-Time
Cdn-Host
X-SD-PageType
X-Pubstack
X-Policy
X-RateLimit-Limit-Second
XM
X-RateLimit-Remaining-Second
X-Req
X-Region-Sid
Ha-Gx-Prefs
Yak-Timeinfo
X-VarnishDD-TTL
X-Service
X-PAYTM-SRV-ID
X-PERF
X-VG-WebCache
Canary
Content-Script-Type
X-Nginx-Cache-Key
X-V-Cache
Esi-Enabled
Content-Style-Type
X-Newrelic-Synthetics
DSUID
Edge-Cache
X-Var-Ttl
X-Nyt-Route
X-Varnishpool
Fastly-SSL
Cdnsip
X-Varnish-Director
Fastly-Backend-Name
X-Tt-Logid
X-Aicache-OS
X-Access
X-Ad-Load-Variation
X-Request-Host
X-Acquia-Purge-Cdn-Unconfigured
X-CacheTTL
X-Varnish-Authentication
X-Wikidot-Backend
X-Render-Time
X-Contensis-Viewer-Groups
X-Server-IP
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-BBC-Edge-Cache-Status
X-Via-Fastly
X-Hash
X-Section
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Backend
X-Sn-Servicetimems
X-Varnish-Beresp-Ttl
X-Human
X-We-Are-Hiring
X-VG-TLSProxy
X-Cache-Aspx
X-GoCache-CacheStatus
Gh-Request-Id
X-DPWN-IS-SECURE
Cluster
On-Server
X-Ig-Push-State
X-Men
Producers
Pramga
Platform
X-Micro-Cache
X-Mly-Id
L
X-Fastly-Backend
Is-Eu
Fastly-GeoIP-CountryCode
Machine
X-Ec-Custom-Error
Country-Code
X-Wikidot-Static-Cache
X-Varnish-Beresp-Status
V-Age
True-Client-Country-4JS
Redirect-Candidate
X-Pool
Web-Mar-Region
X-Dc
X-Proxied-Request
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Host
Cache-Key
RNT-Time
RNT-Machine
X-Location
Apple-News-Services-Request-Url
Req-Svc-Chain
Apple-News-Services-Parsed-Url
X-AIR-PT
Odigeo-Trace-Id
X-Date
Cdn-Requestid
X-Accel-Expires-Debug
Tube-Get-Contents
Tube-Got-Eval
Proxy-Firewall
Click-Count-Action-Start
NGX
Click-Count-Error
Tube-Got-Results
Tube-Return
X-Slack-Shared-Secret-Outcome
X-Up
X-Slack-Backend
X-B3-Trace-ID
Datacenter
X-LB-ID
Debug
X-NodeID
X-Custom-Header
X-Varnish-Hits
X-COUNTRY
X-Ismobilevalue
X-Nananana
X-Refresh
X-ID
X-Cs
X-Akamai-Transformed
Locid
X-CACHE-GROUP
X-Pad
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-DefElseHash
X-Varnish-CookieHashed-On
X-DefHash
X-Amz-Meta-Cb-Modifiedtime
X-Platform-Cluster
X-Platform-Processor
X-LiteSpeed-Tag
X-Platform-Router
X-Client-Ip
Fastly-Drupal-HTML
Mime-Version
SID
X-Via-Popn
CloudFront-Viewer-Country
X-VHOST
X-Via-Popv
Pics-Label
X-HA-Backend
X-Via-Poph
X-Depends
X-M-Log
X-Servedbyhost
X-M-Reqid
X-Cached-By
X-Datadome
X-VC-TTL
X-Old-Content-Length
GeoIP-Latitude
Ngx-Var-Key
X-Parent-Response-Time
X-CACHE-AGE
X-Moov-Xdn-Version
X-Moov-T
X-TH-Server
Fastly-Drupal-Html
X-B3-Parentspanid
X-CDN-Cache-Status
X-LB-NoCache
X-Cache-FS-Status
X-TIME
X-CS
Cross-Origin-Embedder-Policy-Report-Only
X-DynaTrace-JS-Agent
Resin-Trace
GeoIp-Country-Code
Cf-Ipcountry
NtCoent-Length
Server-ID
X-Presslabs-Stats
Cdn
X-Application
X-Vgn-Hpd-Reason
X-External-Request-Id
X-VCache
X-B-Cookie
X-Destination
X-Nc
BehaviorPad-Version
X-Wa
X-User
Uri
X-S-Cookie
Server-Info
Cf-Device-Type
X-Litespeed-Tag
X-ZONE
True-Client-IP
X-Zen-Fury
X-NewRelic-App-Data
X-APP
FSS-Cache
X-Is-Crawler
X-Providence-Cookie
X-Flags
X-Route-Name
X-Varnish-Beresp-TTL
CDN
X-Aspnet-Duration-Ms
X-Sigma
X-Fpc
X-Sigma-Backend
X-Cache-Date
X-IAuth-Set-Uid
X-Instance-Name
X-Rocket-Build-Number
X-Esi
X-HostName
X-TX-ID
X-DynaTrace
X-Content-Length
True-Client-Ip
Srv
X-Srv
X-Vc
X-VServer
X-API-Version
Tcn
Load-Balancing
X-Segment-20210421
X-Dynatrace-Js-Agent
X-Branch-Name
X-HITS
X-Page-View
X-Oracle-DMS-ECID
Serverhost
S-Rt
X-FPC
X-HOST
X-WA
X-Cdn-Forward
GeoIP-Country-Code
X-APP-VERSION
X-B3-Spanid
Ohc-File-Size
Request-ID
X-Dispatch
X-DataCenter
X-Cdn-Cache-Status
X-Dispatcher-Number
X-NC
Hostname
Product
Type
X-RequestId
Vc-Max-Age
Server-Id
X-Sql-Count
X-Http-Reason
X-Sql-Duration-Ms
X-Irp-Debug
X-FL-QIT-DEBUG
Geoip-Latitude
X-Lb-Nocache
Srvid
X-Webkit-Csp-Report-Only
ServerName
Cl-Cache
X-Geo
X-Ckpd-Fst-Backend
X-ServedByHost
WZWS-RAY
X-Bug-Bounty
X-Via-CDN
IsBot
X-SIPLIST1
X-Via-SSL
X-Via-Edge
X-CSRF-TOKEN
DataCenter
Edge-Copy-Time
X-Owner
X-VCL-Version
X-Via-PopN
X-Proxy-CacheRZ
Epwk-X-Cache
Cloudfront-Viewer-Country
PICS-Label
X-Via-PopH
Cross-Origin-Opener-Policy-Report-Only
X-Via-PopV
X-Ha-Backend
X-Core-Mission
CacheControlHeader
Ohc-Cache-HIT
Origin-Trial
XkeyRZ
MIME-Version
X-Cache-Ttl
X-Hit
X-CACHE-KEY
X-App
X-Ua
CountryCode
N-Cache
X-Qloud-Router
X-Correlation-ID
X-Cst
ServerHost
Rtss
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-MSEdge-Flight
X-Amz-Meta-Opti
X-MiniProfiler-Ids
X-MSEdge-Features
X-Lb-Id
X-Fastly-Country-Code
Lb
X-Acquia-Application-Trace
X-Sqd-Ctime
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Sqd-Stime
X-Acquia-Site
Warning
X-Datacenter
Sm-Log-Id
X-Web-Server
X-Service-Response-Time
X-LAGOON
X-Forwarded-Path
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-Amz-Meta-S3b-Last-Modified
X-IN-APIGATEWAY
X-Akamai-Device-Characteristics
X-Limited
X-Vmg-Version
User-Agent
Cneonction
X-Proxy-Cache-La3
X-IN-APIGATEWAYSSL
X-Dw-Trace-Id
X-Cdn-Request-ID
X-Check-Cacheable
Expect-Staple
X-Serial
X-Shop-Environment
X-RAMCache
Akamai-Cache-Status
X-Orig-Expires
X-Akamai-Pragma-Client-IP
X-Th-Server
X-Ramcache
X-Cache-Type
X-Requestid
X-CF-Lambda-Fn
Xkey-La3
Xkeylog
X-Snapshot-Date
X-Tenant
Ngx
X-CF-Lambda-Version