Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-DNS-Prefetch-Control
Accept-CH
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-AspNet-Version
X-Check
X-Drupal-Cache
X-Ua-Compatible
X-Generator
X-Cache-Status
Server-Timing
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Content-Encoding
X-CDN
Upgrade
Status
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Permissions-Policy
X-Via
Host-Header
EagleId
Keep-Alive
Request-Context
X-Cache-Group
X-Robots-Tag
X-Backend
X-UA-Device
X-AH-Environment
X-Hacker
X-Proxy-Cache
X-Server
X-Turbo-Charged-By
X-Rq
X-Age
X-Ws-Request-Id
X-Vhost
Cf-Apo-Via
X-Amz-Version-Id
Xkey
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Server-Powered-By
Ali-Swift-Global-Savetime
Allow
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Cache-Lookup
EagleEye-TraceId
X-WebKit-CSP
X-Host
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Backend-Server
Cf-Railgun
X-Dns-Prefetch-Control
X-Server-Id
X-Readtime
X-Response-Time
Surrogate-Control
X-Akam-SW-Version
X-HW
X-Ruxit-JS-Agent
X-Node
Request-Id
X-Cloud-Trace-Context
X-Litespeed-Cache
X-Country
Content-Location
X-Nginx-Cache-Status
X-Application-Context
Accept-Ch-Lifetime
X-Nginx-Upstream-Cache-Status
X-ASPNET-VERSION
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
Cache-Tag
X-Clacks-Overhead
Rating
X-Amz-Server-Side-Encryption
X-Times
X-PC
X-TtlSet
X-Vname
X-Rack-Cache
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Browser-Type
X-Server-Name
X-Daa-Tunnel
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-SID
Accept-Ch
Nginx-Cache
X-Cache-TTL
X-Powered-By-Plesk
X-Cnection
X-FTR-Request-ID
X-Ac
X-ESI
X-D2id
X-GitHub-Request-Id
X-Element-Page-Cache
Edge-Control
X-Kinja-Build
Verso
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Server
X-CST
AR-CACHE
X-MS-InvokeApp
X-Ser
X-Vcap-Request-Id
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Navigation-Version
X-Upstream
Fastly-Restarts
X-Oneagent-Js-Injection
X-Webkit-Csp
X-ECACHE
SPIisLatency
SPRequestDuration
X-FastCGI-Cache
X-B3-TraceId
X-Mod-Pagespeed
X-Amz-Rid
X-Server-Lifecycle-Phase
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Client-IP
X-SharePointHealthScore
SPRequestGuid
X-ARC
X-Goog-Hash
X-Edge-Location-Klb
X-Kinsta-Cache
X-Middleton-Display
X-Sol
Display
Pagespeed
X-Powered-CMS
X-Ratelimit-Limit
X-Mg-S
X-Amzn-Trace-Id
Edge-Cache-Tag
S
Cache-Status
X-Version
Access-Control-Request-Method
Response
X-Middleton-Response
X-VARITI-CCR
X-Ratelimit-Remaining
X-TTL
RTSS
Realpath
X-Forwarded-For
X-Cache-Key
Cross-Origin-Resource-Policy
X-T
X-Content-Digest
X-NF-Request-ID
X-Ruxit-Js-Agent
Fastcgi-Cache
X-Cached
X-Correlation-Id
X-Recruiting
X-Server-ID
X-ORACLE-DMS-RID
X-MSEdge-Ref
X-Fastly-Request-ID
X-Shield-Request-Id
X-TraceId
MicrosoftSharePointTeamServices
Front-End-Https
X-Forwarded-Proto
X-Ua-Browser
X-PressLabs-Stats
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Frontend
X-LLID
X-HS-Hub-Id
X-HS-Content-Id
Payment
X-HS-Cache-Config
Arr-Disable-Session-Affinity
TP-Cache
Public-Key-Pins
X-Request-Processing-Time
X-Request-Received
Server-Node
Count-Hit
X-Protected-By
MS-Author-Via
Content-MD5
X-GUploader-UploadID
X-HS-Combine-CSS
X-LB-Cache
X-Accel-Expires
X-Newrelic-App-Data
X-RateLimit-Remaining
X-TEC-API-ORIGIN
X-Varnish-TTL
X-TEC-API-VERSION
X-Distributor
X-TEC-API-ROOT
X-NODE
Surrogate-Key
X-Origin-Server
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Ezoic-Cdn
X-ORACLE-DMS-ECID
X-Microsite
X-Request-Handler-Origin-Region
X-HP-Trace-Id
X-HP-Webp
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
X-Jurisdiction
Accept-Charset
X-Content-Security-Policy-Report-Only
MRF-Tech
Mrf-Cache-Status
X-Az
X-AppVersion
X-Www-Served-By
X-Activity-Id
Host
X-B3-TraceId-Primal
Cache-Tags
X-Ua-Device
X-Varnish-Server
X-App-Server
X-Cluster-Name
Retry-After
Cleartype
X-Varnish-Backend
X-Amz-Meta-S3cmd-Attrs
X-Goog-Metageneration
X-Unique-Id
X-FTR-Expires
Filterid
X-Debug
X-Hits
Server-Name
X-Git-Hash
Access-Control-Allow-Method
X-Aspnet-Version
X-Logged-In
X-Varnish-Ttl
X-Load-Cache
X-Upgrade-Enabled
X-Ttl
X-Id
X-NGENIX-Cache
X-Azure-Ref
X-Envoy-Decorator-Operation
X-FB-Debug
X-CSRF-Token
X-Geo-Country
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Hostname
TCN
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Seen-By
X-TT
Section-Io-Cache
X-Proxy
X-B
X-Revision
Healthy
X-Request-Guid
TP-L2-Cache
X-Cache-Control
X-Type
X-Nf-Request-Id
X-Fb-Rlafr
X-Contextid
X-B3-Sampled
Viewport
X-Grace
DC
X-Trace-Id
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
Fastly-SWR
X-Time
Fastly-SIE
X-CCDN-Origin-Time
X-F-Cache
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-N
X-Ratelimit-Reset
Content-Disposition
X-Mobile
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Referer-Policy
Paypal-Debug-Id
X-Varnish-Grace
X-XRDS-LOCATION
X-Amz-Replication-Status
X-Origin-Cache
X-Webkit-CSP
X-Magnolia-Registration
X-Via-JSL
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-DIS-Request-ID
X-Debug-Info
X-Page-Id
X-Wormhole-Sdk
Version
X-Px
X-Oracle-Dms-Ecid
X-Ismobilevalue
Amp-Access-Control-Allow-Source-Origin
X-Datadog-Trace-Id
X-G
X-ProcessESI
X-Content-Options
X-RemovedCookies
X-Datadog-Parent-Id
X-UUID
X-Datadog-Sampling-Priority
X-Adobe-Loc
X-App-Environment
X-Adobe-Content
X-Rid
X-Template
X-Debug-IsPreview
X-Node-Name
X-Debug-IsConnected
X-Rule
X-Region
MS-CV
X-Wix-Request-Id
NGB
Ms-Operation-Id
Cross-Origin-Window-Policy
X-Yottaa-Optimizations
X-Hl-Ver
X-Tumblr-User
X-Yottaa-Metrics
SD-X-WS
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel
X-Datadog-Sampled
X-RTag
VIX-Pulpo-Node
X-Storage
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Source
X-Whom
GEO-INFO
X-Device-Type
X-NYM-Debug-Backend
X-Rendered-As
X-User-Agent
X-Is-Bot
X-Instance
X-Cacheable-TTL
X-Proxy-Cache-Info
X-L-Path
X-B-Cache
X-ServerID
X-Backend-Name
X-Status
X-Signature
X-Environment-Context
Country
X-FW-Server
X-FW-Serve
X-FW-Static
X-FW-Version
X-FW-Dynamic
X-FW-Hash
X-FW-Type
X-Cache-Age
Charset
Countrycode
X-RM-Cache-TTL
SRV
X-IPS-LoggedIn
Front
Akamai-GRN
ServerID
X-Framework
X-Real-IP
X-EdgeConnect-Cache-Status
X-WP-CF-Super-Cache-Active
X-NWS-UUID-VERIFY
X-Cache-Grace
X-ECache
X-AB
X-Xrds-Location
X-Amzn-Remapped-Content-Length
Liferay-Portal
X-Language
X-B3-SpanId
X-Cache-Hit
X-Oracle-Dms-Rid
X-Akamai-Request-ID2
X-Air-Pt
X-Content-Powered-By
X-WebKit-CSP-Report-Only
X-Fastly-Request-Id
X-Api-Version
X-DataDome
X-Servername
X-Air-Trace-Id
Accept-Language
X-Air-Source
X-VC
OT-Force-Account-Verify
X-Air-Hostname
X-Sucuri-ID
X-Sucuri-Cache
X-UA
Xet-Cookie
X-URL
From-Origin
X-VC-Cache
X-Mode
LB
Refresh
X-Cache-Status-Check
Webserver
Backend
Access-Control-Request-Headers
X-Tt-Logid
X-HTML-Minification-Powered-By
X-Nginx-Cache
Upgrade-Insecure-Requests
X-Mg-Request-UUID
X-RCS-CacheZone
X-Handled-By
X-UPSTREAM-Address
X-Cache-Time
X-Rn-Rsrv
X-SaId
Filters
X-SRV
X-JoinUs
X-Rewrite-Enabled
X-Git-Commit
Meta-Geo
X-Container-Uri
X-Cms-Context
X-Webstats-RespID
X-R9-Blue-Green-Version
X-Request-URI
X-PHP-Host
X-Hosted-By
X-Labrador-Cache-Channel
X-S
X-Generated-By
X-RateLimit-Limit
Xserver
X-Origin-Date
X-Forwarded-Host
X-Adobe-Source
Web-Mar-Node
Webcakes-App-Name
Cache
Url
X-Site-Version
X-Scope-Id
Property-Id
Section-Io-Id
Atl-Traceid
Mn-Server-Ip
X-ProxyCache-Key
X-Redis-Cache
X-Reqid
X-ProxyCache-Status
Apigw-Requestid
X-Served-From
TWC-GeoIP-LatLong
X-Shopify-Stage
TWC-Locale-Group
TWC-GeoIP-Country
TWC-Device-Class
ServedBy
TWC-Connection-Speed
TWC-Privacy
X-Web-Node
X-Tcp-Rtt
X-Geo-Region
X-No-Session
X-Fetched-On
X-Logging-Id
X-Tncms
X-Httpd
X-Varnish-Age
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Desktop
X-Is-Tablet
Webcakes-App-Version
X-Lambda-Id
X-Storefront-Renderer-Rendered
X-Provided-By
X-Xfnlog-Site
X-Akamai-Edgescape
X-Accel-Version
X-Skip-Cache
Webcakes-Region
X-Tb
X-Alternate-Cache-Key
X-Origin-Hint
X-Loop
X-Tumblr-Pixel-2
X-Cache-Host
X-Cache-Debug
X-Browser-Name
X-BYPASS-REASON
X-VCT
X-Locale
X-Varnish-Beresp-Grace
X-Say-Cacheable
X-Restarts
X-Detected-As
X-Cluster
X-Origin
X-Proxy-Build
X-Optimistic-Header
X-Format
Selected-Fe
X-SayCDN-TTL
X-Soup
X-Timing-Wait
X-Say-TTL
X-IPLB-Request-ID
X-Cloudmap
X-Proxied
X-AWS-Id
X-Director
X-Extlb
X-IPLB-Instance
X-Frame-Option
X-LJ-Flow-ID
X-ShopId
X-Edge-Location
X-Sorting-Hat-PodId
X-Vcache
X-Varnish-Cache-Hits
X-VWS-Id
X-Cache-Rule
X-RID
Expiry
X-Zipkin-Id
X-Cache-Operation
X-Connection-Hash
X-ShardId
Onion-Location
X-Routing-Service
X-Sorting-Hat-ShopId
X-Ms-Version
X-Cache-Expired-At
X-Ms-Request-Id
X-Upstream-Ct
X-Endurance-Cache-Level
X-Upstream-Ht
X-Aws-Lambda-Call-Status
X-Vcl-Version
X-Lagoon
Source
X-INCAP-ABP
X-GeoCode
Cdn-Requestid
X-WP-CF-Super-Cache-Cookies-Bypass
Frame-Options
WPO-Cache-Status
WPO-Cache-Message
X-GeoCountry
X-CDN-Forward
Priority
X-Azure-Ref-OriginShield
Protected
Environment
X-Fastcgi-Cache
X-Cache-Action
X-Proxy-Cache-Status
X-B3-Traceid
X-Generation-Time
X-Thinkindot-L3
X-CMSURLCustom
Thinkindot-Control
Fastcgi-Useragent
Thinkindot-CacheControl
TDXMobile
CF-IPCountry
Thinkindot-CacheControl-Type
X-Shield-Cache-Expires
X-PHP-Backend
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Origin-TTL
Uber-Trace-Id
X-Origin-CC
X-Cluster-Node
X-App-Version
X-Cdn-Origin
X-Pass-Why
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-ID
X-GEO
Sid
X-Rocket-Nginx-Serving-Static
X-Worker
X-Aspnetmvc-Version
X-Buckets
X-XRDS-Location
X-FB-TRIP-ID
Node
Cache-Tv-Group
Azure-SiteName
Azure-Version
Azure-SlotName
Azure-InstanceId
X-Vercel-Cache
X-Auth-Group-Type
X-Vercel-Id
Azure-RegionName
CDN-PullZone
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
CDN-Uid
Cache-Hits
Cross-Origin-Embedder-Policy
X-Server-W
X-Pad
X-Tumblr-Pixel-3
X-TA-CDN-Provider
Alternate-Protocol
AMP-Access-Control-Allow-Source-Origin
X-Tx-Id
X-DC
X-A
X-Client-Ip
X-Ig-Push-State
X-Content-Age
X-GeoIP-City
X-Conf
Cache-Provider
X-Req
X-Core-Value
X-Dispatcher-Server
Odigeo-Trace-Id
X-Rojux
Candidate-Md5Url
Sslversion
X-Cache-TTL-Remaining
T-Server
Surrogated-Key
X-Cache-NE
X-Ig-Origin-Region
X-Ec-GeoHdr
X-ND-Cache
MD5-Digest
X-Ec-Fail
Magicmarker
PFcat
A
X-DefHash
Origin-Agent-Cluster
X-DefElseHash
X-NodeID
X-D
Lang
X-Service
Rendered-Blocks
X-Custom-Header
X-ScT
X-Op-Id-All
X-Org
X-Origin-Expires
X-Developer
Gannett-Cam-Experience-Id
X-Vdms-Version
Content-Secure-Policy
Ngx.Var.Host
X-Via-Fastly
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Viewer-Country
X-Fastly-Backend
DCR-Decision-By
X-BCube-Filmed-By
X-Bc-Bl
DCR-Processing-Time-Ms
DB-Nickname
X-Bl-Debug
X-Aed
X-Vtex-Remote-Cache
X-Gzip
Meta-Geo-Continent
X-Varnish-CookieINHashed-On
X-SRCache-Key
Fastly-SSL
X-Cache-Id
X-Level-Front-Cache
X-Esi-Check
X-LSADC-Cache
X-Epic-Correlation-Id
X-Generated-On
X-Varnish-CookieHashed-On
X-HN
X-A-Ccd
X-A-Dam
Wxu-Next-Region
X-V-Cache
X-TIM-N
Wxu-Next-Hostname
Wxu-Next-Commit
Mime-Version
X-Cache-Server
User-Cache-Control
X-LiteSpeed-Cache-Control
X-Edge-Server
Fastly-Backend-Name
Esi-Enabled
Edge-Cache
X-Fastly-Cache
X-Eu-Site
Ha-Gx-Prefs
L
Is-Eu
Host-ID
HA-Ipaddr
L5d-Success-Class
X-CGP
W
X-Cache-FS-Status
X-Cache-Bucket
Vix-Hermes-Req-Id
V-Age
Tube-Got-Results
Tube-Return
X-Access
X-Acquia-Purge-Cdn-Unconfigured
X-Bip
X-Backend-Instance
X-Amz-Storage-Class
X-AK-Request-ID
X-Block-Status
X-Aicache-OS
Tube-Got-Eval
Tube-Get-Contents
Powered-By
Producers
X-Csrf-Jwt
Platform
X-Debug-Cache-Fetch
NM-Fastcgi-Cache
X-Debug-Cache-Store
Req-ID
X-Clientip
True-Client-Country-4JS
X-Cache-Info
Ssr
X-CacheTTL
X-FC-Vary-Parameters
Server-Host
X-DPWN-IS-SECURE
Apple-News-Services-Handled
X-Proto
X-Powered-By-VTEX-Cache
X-Fmm-Version
X-VTEX-Cache-Server
X-Pubstack
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Policy
X-Platform
X-Wikidot-Static-Cache
X-Node-Id
XM
X-Origin-Response-Time
X-Wikidot-Backend
X-PAYTM-SRV-ID
X-VTEX-Cache-Time
X-Region-Sid
X-VG-WebCache
X-Tb-Optimization-Total-Bytes-Saved
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Varnish-Hostname
X-Thanos
X-Varnish-Director
X-UA-Device-Type
X-Sn-Servicetimems
X-Server-IP
X-Request-Time
X-VG-TLSProxy
X-SB
X-Scheme
X-Section
X-SD-PageType
X-Mvc-Supplant-Cachable
X-NMSegId
X-Gen-Mode
X-GeoIP
Apple-News-Services-Request-Url
X-Mly-Id
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Click-Count-Error
CDCHOST
Cdnsip
Click-Count-Action-Start
Cdncip
Cdn-Request-Time
Cdn-Host
X-B3-Trace-ID
X-GeoIP-Country-Code
X-Jobs
Country-Code
X-Loc
X-Men
X-Forwarded-Site
X-Micro-Cache
X-HS-Content-Campaign-Id
X-Hnp-Log
X-GeoIP-Region-Code
Adler-Geo
Content-Script-Type
Server-Info
Content-Style-Type
X-Dc
X-Varnish-Beresp-Ttl
HostName
X-HITS
X-Varnish-Beresp-Status
Yak-Timeinfo
BehaviorPad-Version
X-BBC-Edge-Cache-Status
X-Varnishpool
X-Mvc-Supplant-OutputCached
X-Pool
X-Hash
X-Human
X-Nginx-Cache-Key
X-GoCache-CacheStatus
X-Ec-Custom-Error
X-Gdpr
X-Geo-Header
X-Nyt-Route
X-Origin-Time
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Test
X-Request-Start
X-Request-Host
X-CUA
X-Proxied-Request
X-Var-Ttl
X-Date
Proxy-Firewall
Pramga
Origin-EX
Origin-CC
Req-Svc-Chain
X-Cs
Server-Ext
RNT-Time
RNT-Machine
Origin
On-Server
Cache-Key
Fastly-GeoIP-CountryCode
DSUID
Canary
C-Via
Machine
AKAMAI
NGX
Mail-Subject
Server-Hostname
Release
X-App-Name
Web-Mar-Region
X-Accel-Expires-Debug
We-Hiring
Sever-Int
X-NGINX-Cache
X-AIR-PT
X-Cdn-Srv
X-Location
X-Cache-Aspx
Gh-Request-Id
X-Varnish-Authentication
X-Auto-Login
Debug
X-Depends
Cluster
X-Contensis-Viewer-Groups
X-We-Are-Hiring
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
X-Ad-Load-Variation
Fusion-Template-Id
Fusion-Deployment-Id
X-WA-Info
Fusion-Content-Id
X-Varnish-Hits
X-MP-GENERATED-AT
X-Device-Os
X-CLOUD-TRACE-CONTEXT
Redirect-Candidate
X-LB-ID
X-Newrelic-Synthetics
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-HA-Backend
Fastly-Drupal-HTML
X-Via-Poph
X-Via-Popv
X-APP
X-Content-Length
GeoIP-Latitude
X-Via-Popn
Pics-Label
X-Zone
X-RateLimit-Reset
X-VHOST
CloudFront-Viewer-Country
X-NCache
X-Up
X-From
X-Akamai-Transformed
CDN-RequestId
SID
X-CACHE-AGE
X-Cache-Backend
X-Servedbyhost
X-Jungle-Id
X-B3-Parentspanid
X-Nananana
Vc-Max-Age
X-LiteSpeed-Tag
X-Dispatcher-Number
X-Refresh
X-Vdms-Path
X-LB-NoCache
X-Nc
X-Litespeed-Tag
X-Parent-Response-Time
X-CACHE-KEY
X-RequestId
X-ZONE
Fastly-Drupal-Html
Product
X-DynaTrace-JS-Agent
X-CDN-Cache-Status
X-Cached-By
Server-ID
X-Wa
X-Uri
WP-Super-Cache
X-PERF
X-Ckpd-Fst-Backend
X-M-Log
X-VC-TTL
X-Render-Time
Cdn
X-ApacheServer
Resin-Trace
Datacenter
X-Datadome
X-M-Reqid
S-Rt
X-B3-Spanid
GeoIp-Country-Code
X-Bug-Bounty
X-Origin-Cache-Key
X-CS
NtCoent-Length
X-IAuth-Set-Uid
X-Amz-Meta-Cb-Modifiedtime
FSS-Cache
X-Fpc
Uri
ServerName
X-Varnish-Beresp-TTL
X-HubSpot-Correlation-Id
True-Client-Ip
Serverhost
X-Esi
Locid
X-TX-ID
X-SERVER-NAME
X-HostName
X-Nf-Country
X-Nf-Ats-Version
X-Nf-Language
True-Client-IP
X-Srv
X-TT-LOGID
GeoIP-Country-Code
X-Vmg-Version
X-VCache
Tcn
X-Akamai-Device-Characteristics
Srv
X-TIME
X-Dynatrace-Js-Agent
X-Old-Content-Length
X-FPC
ServerHost
X-Cdn-Cache-Status
User-Agent
X-Info
X-Gamma-Serve
X-NewRelic-App-Data
X-Hit
Request-ID
CDN
X-Cdn-Forward
X-Original-Request-Id
X-Response-Served-From
Ngx-Var-Key
CacheControlHeader
X-WA
X-Vc
Xc-Version
X-Vgn-Hpd-Reason
Expect-Staple
Server-Id
X-Moov-Xdn-Version
X-APP-VERSION
X-Moov-T
Hostname
X-COUNTRY
Cneonction
X-Amz-Meta-Opti
X-TH-Server
Srvid
X-NC
X-FL-QIT-DEBUG
X-Webkit-Csp-Report-Only
X-Presslabs-Stats
Cf-Ipcountry
X-VCL-Version
X-V
X-Geo
X-Lb-Nocache
X-Dispatch
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
Geoip-Latitude
X-ServedByHost
Cf-Device-Type
X-Eligible
WZWS-RAY
X-New
X-Platform-Server
X-Rollout
N-Cache
Permission-Policy
PICS-Label
Cloudfront-Viewer-Country
X-Oracle-DMS-ECID
X-Limited
X-Via-PopH
X-App
X-Application
X-Ha-Backend
X-Via-PopV
X-Via-PopN
Origin-Trial
X-User
Cross-Origin-Embedder-Policy-Report-Only
X-B-Cookie
X-S-Cookie
X-Destination
X-External-Request-Id
Ohc-File-Size
X-Ftr-Request-Id
X-Akamai-Pragma-Client-IP
X-Internal-TTL
X-ElasticPress-Query
X-Zen-Fury
X-Proxy-CacheRZ
X-Correlation-ID
X-Ua
XkeyRZ
Rtss
X-MiniProfiler-Ids
X-Instance-Name
X-MSEdge-Flight
X-Check-Cacheable
X-Sqd-Ctime
X-MSEdge-Features
X-EC-Lua
X-Sigma-Backend
X-VTEX-Cache-Backend-Header-Time
X-Path
Cl-Cache
X-Lb-Id
Epwk-X-Cache
X-Sigma
X-Sqd-Stime
X-VTEX-Cache-Backend-Connect-Time
X-Serial
X-Litespeed-Cache-Control
X-Rocket-Build-Number
X-Cache-Date
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Lb
X-Segment-20210421
X-SIPLIST1
Sm-Log-Id
X-Datacenter
X-Via-SSL
Edge-Copy-Time
Timeexpire
X-API-Version
X-VServer
X-Service-Response-Time
IsBot
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Branch-Name
X-Acquia-Application-Trace
X-Via-CDN
Cmstype
Cmsid
X-Web-Server
X-Via-Edge
X-Acquia-Site
X-CDN-Origin
Servername
CountryCode
X-LAGOON
X-CSRF-TOKEN
Pragrma
X-Cdn-Request-ID
X-Irp-Debug
X-DynaTrace
X-Traceid
Fl-Custom-Application
X-Amz-Meta-S3b-Last-Modified
Warning
X-Amz-Meta-Sha256
X-Udemy-Cache-App-Namespace
X-Dw-Trace-Id
Ngx
X-Snapshot-Date
X-RAMCache
X-Th-Server
X-Ramcache
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Ohc-Cache-HIT
Wpo-Cache-Message
Wpo-Cache-Status
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Origin-Upstream-Status
X-Shardid
X-Shopid
X-Fastly-Backend-Reqs