Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-DNS-Prefetch-Control
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Via
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
X-UA-Device
X-Robots-Tag
Permissions-Policy
X-Server
X-Hacker
X-AH-Environment
X-Proxy-Cache
X-Turbo-Charged-By
Xkey
X-Rq
X-Ws-Request-Id
X-Age
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-Swift-CacheTime
X-Swift-SaveTime
Allow
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
P3p
X-Page-Speed
X-OneAgent-JS-Injection
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
Cf-Railgun
EagleEye-TraceId
X-Backend-Server
X-Host
X-Server-Id
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
X-Ruxit-JS-Agent
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Litespeed-Cache
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Nginx-Cache-Status
X-Country
X-NWS-LOG-UUID
Accept-Ch-Lifetime
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
Cache-Tag
X-Clacks-Overhead
X-CST
X-Url
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-Times
X-FTR-Request-ID
X-PC
X-TtlSet
X-Vname
Nginx-Cache
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Webkit-Csp
X-Server-Name
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-Cnection
X-ESI
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
X-GitHub-Request-Id
Edge-Control
X-Element-Page-Cache
X-D2id
X-Ac
Verso
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-MS-InvokeApp
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Oneagent-Js-Injection
X-Upstream
X-ECACHE
X-Cache-TTL
X-Vcap-Request-Id
X-Abt-Application-Version
AR-CACHE
X-Ser
X-Navigation-Version
X-FastCGI-Cache
X-B3-TraceId
X-Dw-Request-Base-Id
SPRequestDuration
SPIisLatency
X-Mod-Pagespeed
X-NF-Request-ID
Fastly-Restarts
SPRequestGuid
X-SharePointHealthScore
X-Amz-Rid
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Client-IP
X-Edge-Location-Klb
X-Kinsta-Cache
X-Mg-S
Edge-Cache-Tag
Pagespeed
X-Middleton-Display
Display
X-Sol
S
X-Powered-CMS
X-Goog-Hash
X-ARC
Cache-Status
X-Amzn-Trace-Id
X-Version
Access-Control-Request-Method
X-Middleton-Response
Response
X-VARITI-CCR
X-Ratelimit-Limit
X-Cache-Key
X-Ruxit-Js-Agent
X-PDP-UNCACHING-HASH
RTSS
X-Content-Digest
X-TraceId
X-Fastly-Request-ID
Cross-Origin-Resource-Policy
X-T
X-Forwarded-For
Realpath
X-Recruiting
X-Aws-Lambda-Call-Status
X-Correlation-Id
X-RateLimit-Remaining
X-Ratelimit-Remaining
X-TTL
Fastcgi-Cache
X-Cached
Front-End-Https
X-MSEdge-Ref
X-ORACLE-DMS-RID
MS-Author-Via
Content-MD5
X-Shield-Request-Id
X-Protected-By
X-Forwarded-Proto
X-HS-Content-Id
X-Ua-Browser
X-HS-Cache-Config
X-HS-Hub-Id
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend-Server
X-Request-Processing-Time
Server-Node
X-Request-Received
Public-Key-Pins
Payment
TP-Cache
X-LLID
MicrosoftSharePointTeamServices
X-Frontend
X-Varnish-TTL
X-HS-Combine-CSS
Arr-Disable-Session-Affinity
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-FTR-Expires
X-Distributor
X-Accel-Expires
X-Kong-Upstream-Latency
Count-Hit
X-Kong-Proxy-Latency
X-GUploader-UploadID
X-PressLabs-Stats
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Origin-Server
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Server-ID
X-LB-Cache
X-NODE
X-Ezoic-Cdn
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Request-Handler-Origin-Region
X-Microsite
X-Az
X-AppVersion
X-Activity-Id
X-Ttl
Accept-Ch
Host
X-Varnish-Server
X-Cluster-Name
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
X-App-Server
X-Www-Served-By
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Amz-Meta-S3cmd-Attrs
Cache-Tags
Retry-After
Accept-Charset
X-ORACLE-DMS-ECID
Server-Name
X-Ua-Device
Cleartype
X-Newrelic-App-Data
X-Goog-Metageneration
X-Hits
X-Envoy-Decorator-Operation
X-Hostname
X-ASPNET-VERSION
Filterid
X-Unique-Id
Referer-Policy
X-Upgrade-Enabled
X-CSRF-Token
X-Git-Hash
Access-Control-Allow-Method
X-Azure-Ref
X-NGENIX-Cache
X-Varnish-Ttl
X-Load-Cache
X-Geo-Country
TP-L2-Cache
TCN
X-Seen-By
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Logged-In
X-Debug
X-Proxy
X-CCDN-CacheTTL
X-DIS-Request-ID
X-F-Cache
Section-Io-Cache
X-B
X-Amzn-RequestId
X-FB-Debug
X-Amz-Apigw-Id
X-Request-Guid
X-Grace
X-Trace-Id
X-Revision
X-Cache-Control
Healthy
DC
X-B3-Sampled
X-Type
X-Contextid
X-Time
X-TT
X-Fb-Rlafr
X-Id
Viewport
Paypal-Debug-Id
X-Mobile
X-N
X-Debug-Info
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Surrogate-Key
X-Page-Id
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
Fastly-SWR
X-Px
Fastly-SIE
X-XRDS-LOCATION
Content-Disposition
X-Whom
X-Oracle-Dms-Ecid
X-Via-JSL
X-Origin-Cache
Version
X-Varnish-Grace
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Content-Options
X-Datadog-Parent-Id
X-Webkit-CSP
X-Origin-Cache-Key
Charset
X-Magnolia-Registration
X-Template
X-Wix-Request-Id
X-Cache-Grace
X-Amz-Replication-Status
X-App-Environment
X-ProcessESI
X-Node-Name
X-RemovedCookies
X-B-Cache
X-Signature
X-Tumblr-User
X-UUID
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Rule
X-Tumblr-Pixel
MS-CV
Ms-Operation-Id
X-RTag
X-G
X-Hl-Ver
SRV
X-Debug-IsConnected
X-Datadog-Sampled
VIX-Pulpo-Node
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-EdgeConnect-Cache-Status
VIX-Pulpo-Upstream-Status
X-Debug-IsPreview
SD-X-WS
ServerID
X-Adobe-Loc
X-Adobe-Content
X-Backend-Name
X-FW-Static
X-Instance
X-FW-Version
X-FW-Type
X-Storage
X-FW-Server
X-FW-Dynamic
X-Cache-Age
X-FW-Hash
X-FW-Serve
X-Is-Bot
X-Device-Type
X-NYM-Debug-Backend
X-Proxy-Cache-Info
X-Rendered-As
X-Rid
GEO-INFO
X-Cacheable-TTL
NGB
X-Region
X-User-Agent
X-Real-IP
X-L-Path
X-Cache-Hit
Country
X-B3-SpanId
X-Environment-Context
X-Source
X-Status
X-Language
X-ServerID
X-NWS-UUID-VERIFY
X-IPS-LoggedIn
Countrycode
Liferay-Portal
X-Amzn-Remapped-Content-Length
X-Xrds-Location
X-URL
Cross-Origin-Window-Policy
Akamai-GRN
X-Oracle-Dms-Rid
X-WP-CF-Super-Cache-Active
X-RateLimit-Limit
X-Sucuri-Cache
X-Sucuri-ID
X-RM-Cache-TTL
Amp-Access-Control-Allow-Source-Origin
Front
OT-Force-Account-Verify
X-Wormhole-Sdk
X-Servername
X-Framework
X-UA
X-Air-Pt
X-VC-Cache
From-Origin
X-Ratelimit-Reset
X-Air-Source
X-Air-Trace-Id
X-AB
X-Air-Hostname
Upgrade-Insecure-Requests
X-Content-Powered-By
X-Mode
Backend
Xet-Cookie
X-Akamai-Request-ID2
X-WebKit-CSP-Report-Only
X-VC
Refresh
X-INCAP-ABP
X-Cache-Time
X-RateLimit-Reset
X-Handled-By
X-Nginx-Cache
X-DataDome
X-Edge-Location
X-Endurance-Cache-Level
Accept-Language
X-Rn-Rsrv
X-SaId
X-Rewrite-Enabled
X-SRV
Meta-Geo
Filters
X-RCS-CacheZone
X-RID
X-JoinUs
X-UPSTREAM-Address
Cache
X-Xfnlog-Site
X-VWS-Id
X-Provided-By
X-Git-Commit
Property-Id
TWC-Connection-Speed
ServedBy
X-Webstats-RespID
X-Labrador-Cache-Channel
X-No-Session
X-Origin-Date
X-Origin-Hint
X-PHP-Host
Frame-Options
X-LJ-Flow-ID
TWC-GeoIP-Country
TWC-Device-Class
X-Cache-Operation
X-Cache-Rule
Webcakes-Region
X-Tumblr-Pixel-2
X-AWS-Id
X-Container-Uri
X-Cluster
TWC-GeoIP-LatLong
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-Reqid
TWC-Locale-Group
Webserver
WPO-Cache-Message
WPO-Cache-Status
X-Fastly-Request-Id
X-R9-Blue-Green-Version
X-Restarts
X-Redis-Cache
X-HTML-Minification-Powered-By
X-Accel-Version
Web-Mar-Node
X-Adobe-Source
X-Akamai-Edgescape
X-Cms-Context
X-Cache-Debug
Url
Section-Io-Id
X-Locale
X-Logging-Id
X-IPLB-Request-ID
X-IPLB-Instance
Mn-Server-Ip
X-Web-Node
Atl-Traceid
LB
X-Zipkin-Id
X-Hosted-By
X-Scope-Id
X-Cloudmap
X-Generated-By
X-Extlb
X-Lambda-Id
X-Tb
X-Site-Version
X-Fetched-On
X-Served-From
X-Proxied
X-Varnish-Age
X-Routing-Service
X-Ms-Version
X-Ms-Request-Id
X-Cache-Status-Check
X-Upstream-Ht
X-Soup
X-Frame-Option
X-Origin
X-Tncms
Selected-Fe
X-Skip-Cache
X-Loop
X-BYPASS-REASON
X-Director
X-VCT
X-Vcache
X-Httpd
X-SayCDN-TTL
X-Say-TTL
X-Upstream-Ct
X-Say-Cacheable
X-Azure-Ref-OriginShield
X-CDN-Forward
X-Timing-Wait
X-Forwarded-Host
X-Format
X-Varnish-Cache-Hits
Apigw-Requestid
X-Proxy-Build
X-ProxyCache-Status
X-ProxyCache-Key
Xserver
X-Varnish-Beresp-Grace
X-Browser-Name
X-Is-Supported-Browser
Access-Control-Request-Headers
X-Is-Desktop
X-Cache-Host
X-GeoCountry
X-Tcp-Rtt
X-Geo-Region
X-Shopify-Stage
X-GeoCode
X-Detected-As
X-Alternate-Cache-Key
X-S
X-Is-Mobile
X-Is-Tablet
X-Storefront-Renderer-Rendered
Cache-Hits
X-Origin-TTL
X-Origin-CC
X-Drupal-Cache-Tags
X-Sorting-Hat-ShopId
X-ShardId
X-Drupal-Cache-Contexts
X-Shield-Cache-Expires
X-ShopId
X-Sorting-Hat-PodId
X-CMSURLCustom
X-Generation-Time
TDXMobile
X-Optimistic-Header
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Thinkindot-L3
X-Lagoon
X-Request-URI
Source
X-Ismobilevalue
X-Cdn-Origin
Fastcgi-Useragent
X-WP-CF-Super-Cache-Cookies-Bypass
Onion-Location
X-TA-CDN-Provider
Protected
X-Api-Version
X-ID
X-Worker
X-Connection-Hash
X-Vercel-Cache
X-Buckets
X-Vercel-Id
Expiry
X-Pass-Why
X-Vcl-Version
Azure-RegionName
Azure-SiteName
Azure-InstanceId
X-Rocket-Nginx-Serving-Static
Azure-SlotName
Azure-Version
X-Cache-Expired-At
X-B3-Traceid
X-Tt-Logid
Cdn-Requestid
Node
X-Fastcgi-Cache
X-App-Version
CDN-CachedAt
X-PHP-Backend
CDN-EdgeStorageId
CDN-Cache
CDN-RequestPullCode
CDN-RequestPullSuccess
X-GEO
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
Cross-Origin-Embedder-Policy
X-Mg-Request-UUID
X-Tumblr-Pixel-3
Priority
Environment
X-ECache
X-Cache-Action
Uber-Trace-Id
X-Proxy-Cache-Status
AMP-Access-Control-Allow-Source-Origin
X-Aspnetmvc-Version
X-Cluster-Node
X-Cache-Server
X-Server-W
X-Urbn-Site-Id
Sid
Locale
X-Urbn-Context-Path
X-XRDS-Location
DB-Nickname
Alternate-Protocol
CF-IPCountry
Cache-Tv-Group
User-Cache-Control
X-Tx-Id
X-FB-TRIP-ID
X-Jobs
X-DC
HostName
Fusion-Template-Id
X-Auth-Group-Type
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Deployment-Id
X-LSADC-Cache
X-A-Dgt
X-A-Dcw
X-Vdms-Version
X-Epic-Correlation-Id
X-A-Dam
X-Aed
X-Esi-Check
X-A-Wwc
X-Bl-Debug
Candidate-Md5Url
X-GeoIP-City
Wxu-Next-Region
X-A
X-Gen-Mode
X-Generated-On
X-A-Ccd
X-D
X-BCube-Filmed-By
X-Content-Age
X-Bc-Bl
X-Conf
X-Vtex-Remote-Cache
X-Block-Status
X-Cache-Id
X-Cache-NE
X-Custom-Header
Wxu-Next-Commit
X-Device-Os
X-Dispatcher-Server
X-Ec-Fail
X-Developer
X-Viewer-Country
A
X-TIM-N
X-Ec-GeoHdr
Wxu-Next-Hostname
X-ScT
Content-Secure-Policy
X-Gzip
X-Origin-Expires
X-Org
X-SRCache-Key
X-Op-Id-All
Ngx.Var.Host
Rendered-Blocks
X-SB
Edge-Cache
Origin-Agent-Cluster
Origin
Odigeo-Trace-Id
X-Rojux
DCR-Decision-By
DCR-Processing-Time-Ms
X-V-Cache
Gannett-Cam-Experience-Id
X-Ig-Push-State
X-Level-Front-Cache
X-Ig-Origin-Region
Magicmarker
Lang
X-Hnp-Log
T-Server
Surrogated-Key
Sslversion
X-UA-Device-Type
Meta-Geo-Continent
X-ND-Cache
X-NCache
MD5-Digest
X-MP-GENERATED-AT
X-Client-Ip
X-Origin-Response-Time
X-Nf-Request-Id
X-Bip
NM-Fastcgi-Cache
Req-ID
X-AK-Request-ID
X-Amz-Storage-Class
Sever-Int
Ssr
Vix-Hermes-Req-Id
V-Age
Server-Hostname
Server-Host
X-Auto-Login
Origin-EX
PFcat
Powered-By
X-App-Name
Server-Ext
Origin-CC
X-Debug-Cache-Store
X-Platform
X-PAYTM-SRV-ID
X-Policy
X-Powered-By-VTEX-Cache
X-Pubstack
X-Proto
X-Origin-Time
X-Nyt-Route
X-Mvc-Supplant-Cachable
X-VarnishDD-TTL
X-Nginx-Cache-Key
X-NMSegId
X-Node-Id
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Tb-Optimization-Total-Bytes-Saved
X-Test
X-Thanos
X-SD-PageType
X-Scheme
X-Region-Sid
X-Varnish-Hostname
X-Req
X-Request-Time
X-Varnish-Director
X-Loc
X-HS-Content-Campaign-Id
X-VTEX-Cache-Time
X-Clientip
X-Core-Value
X-VTEX-Cache-Server
X-Edge-Server
X-Debug-Cache-Fetch
X-Cdn-Srv
X-Cache-TTL-Remaining
XM
X-Fastly-Backend
X-Wikidot-Static-Cache
X-Cache-Info
X-Wikidot-Backend
X-Fastly-Cache
X-Via-Fastly
X-GeoIP-Country-Code
X-GeoIP
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-HN
X-Geo-Header
Host-ID
X-Fmm-Version
X-FC-Vary-Parameters
X-VG-WebCache
X-Forwarded-Site
X-Gdpr
X-Cache-Bucket
X-Backend-Instance
X-Service
Cdnsip
Content-Script-Type
Country-Code
Fastly-Backend-Name
Cdncip
Cdn-Request-Time
Cache-Provider
C-Via
CDCHOST
Cdn-Host
AKAMAI
Fastly-SSL
Content-Style-Type
X-Varnish-Beresp-Ttl
X-Mvc-Supplant-OutputCached
X-DefElseHash
X-DefHash
X-Jungle-Id
X-Sn-Servicetimems
X-Server-IP
X-Cache-Backend
X-Cache-Aspx
X-Pool
X-Men
X-BBC-Edge-Cache-Status
X-Zone
X-Micro-Cache
Apple-News-Services-Host
X-Ad-Load-Variation
X-Mly-Id
X-Acquia-Purge-Cdn-Unconfigured
X-Location
X-Aicache-OS
Adler-Geo
CDN-RequestId
Apple-News-Services-Handled
X-NodeID
X-CacheTTL
Yak-Timeinfo
X-Varnish-Authentication
X-Ec-Custom-Error
X-DPWN-IS-SECURE
X-Varnish-Beresp-Status
X-Pad
X-Var-Ttl
X-Eu-Site
X-From
X-Request-Host
X-LiteSpeed-Cache-Control
X-Section
X-Varnishpool
X-CUA
X-CGP
X-Human
X-We-Are-Hiring
X-Request-Start
X-WA-Info
X-Contensis-Viewer-Groups
X-Csrf-Jwt
HA-Ipaddr
X-Access
X-VG-TLSProxy
X-Proxied-Request
X-B3-Trace-ID
Click-Count-Action-Start
Esi-Enabled
DSUID
On-Server
Fastly-GeoIP-CountryCode
True-Client-Country-4JS
Gh-Request-Id
Mail-Subject
Click-Count-Error
Platform
Producers
RNT-Machine
Req-Svc-Chain
RNT-Time
Pramga
Apple-News-Services-Parsed-Url
Cluster
Release
X-Varnish-Remaining-TTL
Is-Eu
We-Hiring
L
Web-Mar-Region
X-Varnish-CookieHashed-On
Apple-News-Services-Request-Url
Cache-Key
Canary
W
L5d-Success-Class
Tube-Get-Contents
Ha-Gx-Prefs
Tube-Got-Eval
Tube-Got-Results
Tube-Return
Machine
X-Varnish-CookieINHashed-On
X-HITS
Mime-Version
X-Tec-Api-Origin
X-Slack-Backend
X-Tec-Api-Version
X-Up
X-Dc
Proxy-Firewall
X-Tec-Api-Root
X-Hash
X-Depends
X-Slack-Shared-Secret-Outcome
X-Vdms-Path
X-Accel-Expires-Debug
NGX
X-Date
WP-Super-Cache
X-Newrelic-Synthetics
X-Uri
X-AIR-PT
X-NGINX-Cache
Debug
X-Cs
X-Ah-Environment
Redirect-Candidate
X-LB-ID
SID
X-Refresh
X-Varnish-Hits
X-PERF
X-Render-Time
X-ApacheServer
X-CACHE-GROUP
X-Cache-FS-Status
Fastly-Drupal-HTML
X-Original-Request-Id
CloudFront-Viewer-Country
X-Response-Served-From
X-Akamai-Transformed
Pics-Label
X-Nananana
X-Via-Popn
X-Servedbyhost
X-Via-Poph
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-HA-Backend
X-Via-Popv
X-TT-LOGID
GeoIP-Latitude
Server-Info
X-VHOST
X-CACHE-AGE
X-VC-TTL
X-M-Reqid
X-M-Log
X-Litespeed-Tag
BehaviorPad-Version
X-Datadome
Locid
X-LB-NoCache
X-Parent-Response-Time
X-B3-Parentspanid
X-APP
Datacenter
X-Amz-Meta-Cb-Modifiedtime
X-CS
Fastly-Drupal-Html
X-Cached-By
X-Wa
X-CDN-Cache-Status
X-IAuth-Set-Uid
X-Nc
X-Content-Length
Server-ID
Cdn
Cf-Ipcountry
X-DynaTrace-JS-Agent
X-LiteSpeed-Tag
X-Platform-Router
X-Platform-Cluster
Ngx-Var-Key
GeoIp-Country-Code
X-Platform-Processor
Resin-Trace
X-Old-Content-Length
X-NewRelic-App-Data
X-Vgn-Hpd-Reason
X-COUNTRY
X-VCache
NtCoent-Length
X-TH-Server
X-Moov-Xdn-Version
X-Fpc
X-ZONE
Uri
FSS-Cache
X-Moov-T
X-Varnish-Beresp-TTL
Vc-Max-Age
X-Dispatcher-Number
True-Client-Ip
Serverhost
X-TIME
True-Client-IP
Cross-Origin-Embedder-Policy-Report-Only
X-Esi
X-RequestId
X-TX-ID
X-HostName
X-SERVER-NAME
CDN
X-Srv
Product
X-Dynatrace-Js-Agent
GeoIP-Country-Code
X-B-Cookie
Cf-Device-Type
X-Application
S-Rt
Tcn
X-Destination
X-External-Request-Id
X-User
X-S-Cookie
X-Oracle-DMS-ECID
X-Vc
X-FPC
X-Zen-Fury
Srv
X-Ckpd-Fst-Backend
X-HOST
X-B3-Spanid
X-Cdn-Cache-Status
Request-ID
X-API-Version
X-Presslabs-Stats
X-WA
X-Rocket-Build-Number
X-Nf-Ats-Version
X-Instance-Name
X-Nf-Language
X-Sigma
X-Sigma-Backend
X-Webkit-Csp-Report-Only
X-Dispatch
ServerName
X-Nf-Country
X-NC
X-Cache-Date
X-Bug-Bounty
X-CACHE-KEY
X-Cdn-Forward
Hostname
X-VServer
Server-Id
CacheControlHeader
X-HubSpot-Correlation-Id
X-APP-VERSION
Geoip-Latitude
X-Branch-Name
X-Segment-20210421
Ohc-File-Size
X-FL-QIT-DEBUG
Srvid
Load-Balancing
X-Geo
X-Lb-Nocache
X-DynaTrace
Origin-Trial
DataCenter
X-Vmg-Version
User-Agent
X-DataCenter
X-ServedByHost
X-Akamai-Device-Characteristics
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Ha-Backend
X-VCL-Version
Epwk-X-Cache
Cloudfront-Viewer-Country
ServerHost
X-Info
Type
X-Gamma-Serve
X-Is-Crawler
X-Route-Name
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Cache-Ttl
X-Irp-Debug
X-Ua
X-App
Cross-Origin-Opener-Policy-Report-Only
X-Correlation-ID
X-Limited
Xc-Version
PICS-Label
Rtss
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Page-View
X-Lb-Id
Expect-Staple
X-Via-SSL
X-Via-Edge
Ohc-Cache-HIT
X-Via-CDN
Cl-Cache
Cneonction
X-Owner
X-MiniProfiler-Ids
Edge-Copy-Time
X-Sql-Count
X-Sql-Duration-Ms
Lb
X-Http-Reason
Sm-Log-Id
X-SIPLIST1
X-Core-Mission
X-Service-Response-Time
X-Qloud-Router
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Warning
Cmstype
Timeexpire
Cmsid
X-MSEdge-Features
X-Sqd-Ctime
X-Sqd-Stime
X-Amz-Meta-Opti
X-Acquia-Site
X-Acquia-Application-Trace
X-Datacenter
X-Web-Server
IsBot
X-MSEdge-Flight
CountryCode
X-Litespeed-Cache-Control
Servername
X-CSRF-TOKEN
X-LAGOON
XkeyRZ
X-Requestid
X-Origin-Upstream-Status
X-Shardid
X-Proxy-CacheRZ
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Shopid
MIME-Version
X-Akamai-Pragma-Client-IP
X-Dw-Trace-Id
X-IN-APIGATEWAY
Ngx
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Sha256
X-IN-APIGATEWAYSSL
X-Snapshot-Date
X-Check-Cacheable
X-RAMCache
X-Serial
X-Th-Server
X-Ramcache
X-Udemy-Cache-App-Namespace