Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Expect-CT
Accept-Ranges
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
Accept-CH
X-Runtime
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Request-ID
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
X-Amz-Request-Id
X-Amz-Id-2
X-Via
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-Cache-Group
Permissions-Policy
X-Robots-Tag
X-AH-Environment
X-UA-Device
X-Server
X-Hacker
X-Proxy-Cache
X-Turbo-Charged-By
Xkey
X-Rq
X-Ws-Request-Id
X-Age
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-Swift-CacheTime
X-Swift-SaveTime
Allow
X-Server-Powered-By
X-LiteSpeed-Cache
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-OneAgent-JS-Injection
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
Cf-Railgun
X-Host
EagleEye-TraceId
X-Backend-Server
X-Server-Id
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-Ruxit-JS-Agent
X-HW
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Application-Context
X-Nginx-Cache-Status
X-Country
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
Cache-Tag
X-Litespeed-Cache
X-Clacks-Overhead
Rating
X-CST
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-Vname
X-TtlSet
X-PC
X-FTR-Request-ID
X-Webkit-Csp
Nginx-Cache
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Edge
X-Mcache
X-Midtier
X-Server-Name
X-Browser-Type
X-Powered-By-Plesk
X-Cnection
X-ESI
X-D2id
X-GitHub-Request-Id
AR-PoweredBy
AR-SID
X-Element-Page-Cache
AR-Request-ID
AR-ATIME
X-Ac
Edge-Control
Verso
X-MS-InvokeApp
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Upstream
Accept-Ch
X-ECACHE
X-Cache-TTL
X-Vcap-Request-Id
X-Ser
X-Navigation-Version
AR-CACHE
X-FastCGI-Cache
X-Abt-Application-Version
X-Oneagent-Js-Injection
X-Dw-Request-Base-Id
X-B3-TraceId
SPRequestDuration
SPIisLatency
X-NF-Request-ID
Fastly-Restarts
X-Mod-Pagespeed
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Client-IP
X-Edge-Location-Klb
X-Kinsta-Cache
Edge-Cache-Tag
X-Mg-S
X-Goog-Hash
Display
X-Middleton-Display
X-Sol
Pagespeed
S
X-Powered-CMS
X-ARC
X-Ratelimit-Limit
Cache-Status
X-Version
X-Amzn-Trace-Id
Access-Control-Request-Method
X-Middleton-Response
Response
X-VARITI-CCR
X-PDP-UNCACHING-HASH
X-Cache-Key
X-Fastly-Request-ID
X-TTL
X-Content-Digest
RTSS
X-TraceId
X-T
Cross-Origin-Resource-Policy
X-Ruxit-Js-Agent
X-Ratelimit-Remaining
Realpath
X-Forwarded-For
X-Recruiting
X-Ua-Device
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Cached
X-RateLimit-Remaining
X-Correlation-Id
Front-End-Https
X-MSEdge-Ref
MS-Author-Via
X-Shield-Request-Id
Content-MD5
X-Varnish-TTL
X-Protected-By
X-Ua-Browser
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Forwarded-Proto
X-Aws-Lambda-Call-Status
Public-Key-Pins
Server-Node
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-Request-Received
X-Request-Processing-Time
X-FTR-Cache-Status
X-Frontend
X-FTR-Balancer
MicrosoftSharePointTeamServices
Payment
TP-Cache
X-LLID
X-PressLabs-Stats
Arr-Disable-Session-Affinity
X-HS-Combine-CSS
X-Server-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Kong-Proxy-Latency
X-FTR-Expires
X-Kong-Upstream-Latency
Count-Hit
X-GUploader-UploadID
X-Distributor
X-Accel-Expires
X-NODE
X-Origin-Server
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-LB-Cache
X-Ezoic-Cdn
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Microsite
X-Request-Handler-Origin-Region
X-Az
X-Activity-Id
X-AppVersion
X-Varnish-Server
Host
X-ORACLE-DMS-ECID
X-App-Server
Cache-Tags
X-Cluster-Name
X-Www-Served-By
X-Varnish-Backend
Accept-Charset
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Retry-After
X-Content-Security-Policy-Report-Only
X-Amz-Meta-S3cmd-Attrs
X-Newrelic-App-Data
Server-Name
Cleartype
X-Goog-Metageneration
X-ASPNET-VERSION
X-Hits
Filterid
X-Envoy-Decorator-Operation
X-Unique-Id
X-CSRF-Token
Access-Control-Allow-Method
X-Hostname
X-Git-Hash
Referer-Policy
X-Azure-Ref
X-Upgrade-Enabled
X-NGENIX-Cache
X-Geo-Country
X-Load-Cache
X-Ttl
X-Tt-Trace-Tag
X-Tt-Trace-Host
TP-L2-Cache
X-Logged-In
X-Hcs-Proxy-Type
X-Debug
X-Id
X-CCDN-Origin-Time
X-Seen-By
X-CCDN-CacheTTL
X-Proxy
X-FB-Debug
X-Time
X-Varnish-Ttl
DC
X-Amzn-RequestId
X-B
X-Request-Guid
X-Amz-Apigw-Id
X-F-Cache
X-B3-Sampled
X-Trace-Id
X-Revision
X-XRDS-LOCATION
X-Grace
Healthy
X-Type
Section-Io-Cache
X-Fb-Rlafr
X-Cache-Control
TCN
X-TT
X-DIS-Request-ID
X-Contextid
Viewport
Paypal-Debug-Id
X-Mobile
X-N
Surrogate-Key
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Goog-Storage-Class
X-Debug-Info
X-Page-Id
Fastly-SWR
Fastly-SIE
X-Px
Content-Disposition
X-Whom
X-Webkit-CSP
Version
X-Via-JSL
X-Varnish-Grace
X-Origin-Cache
X-Content-Options
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Template
X-Magnolia-Registration
Charset
X-Oracle-Dms-Ecid
X-Cache-Grace
X-Amz-Replication-Status
X-Wix-Request-Id
X-App-Environment
X-Cache-Age
X-RemovedCookies
X-ProcessESI
X-Rule
X-UUID
MS-CV
Ms-Operation-Id
X-RTag
X-Node-Name
VIX-Pulpo-Node
X-Tumblr-User
X-Tumblr-Pixel
X-Datadog-Sampled
VIX-Pulpo-Upstream-Status
SD-X-WS
X-Source
X-B-Cache
X-Tumblr-Pixel-0
X-Signature
X-EdgeConnect-Cache-Status
X-Tumblr-Pixel-1
X-Hl-Ver
X-Debug-IsConnected
X-Environment-Context
X-L-Path
X-Yottaa-Metrics
X-Cacheable-TTL
X-Backend-Name
SRV
X-Instance
X-User-Agent
X-Region
X-Storage
ServerID
X-Yottaa-Optimizations
X-Debug-IsPreview
X-NWS-UUID-VERIFY
X-G
Country
X-Real-IP
GEO-INFO
X-Status
X-ServerID
X-Rendered-As
X-Proxy-Cache-Info
X-Language
X-FW-Serve
X-FW-Hash
NGB
X-Adobe-Loc
X-FW-Server
X-FW-Static
X-Is-Bot
X-FW-Version
X-FW-Type
X-FW-Dynamic
X-Adobe-Content
X-Cache-Hit
X-Device-Type
X-NYM-Debug-Backend
X-B3-SpanId
X-IPS-LoggedIn
Countrycode
X-Rid
X-Amzn-Remapped-Content-Length
Liferay-Portal
Cross-Origin-Window-Policy
Akamai-GRN
X-Origin-Cache-Key
X-Sucuri-ID
X-Sucuri-Cache
X-WP-CF-Super-Cache-Active
Front
X-RM-Cache-TTL
X-Wormhole-Sdk
OT-Force-Account-Verify
X-Servername
X-Oracle-Dms-Rid
X-Framework
X-UA
X-Ratelimit-Reset
From-Origin
X-RateLimit-Limit
X-AB
X-VC-Cache
X-VC
X-Mode
X-WebKit-CSP-Report-Only
X-Air-Source
Xet-Cookie
Backend
X-Content-Powered-By
X-Air-Trace-Id
Amp-Access-Control-Allow-Source-Origin
X-Air-Hostname
Upgrade-Insecure-Requests
X-Akamai-Request-ID2
X-Xrds-Location
X-Air-Pt
X-URL
X-Nginx-Cache
Refresh
X-Cache-Time
X-Handled-By
X-RID
X-INCAP-ABP
X-Endurance-Cache-Level
X-Edge-Location
Accept-Language
Meta-Geo
Filters
Cache
X-RCS-CacheZone
X-SaId
X-Rn-Rsrv
X-RateLimit-Reset
X-JoinUs
X-UPSTREAM-Address
X-Rewrite-Enabled
X-Xfnlog-Site
X-No-Session
X-Zipkin-Id
X-Origin-Hint
Property-Id
X-Provided-By
X-Cache-Rule
X-Lambda-Id
X-Hosted-By
X-Cache-Operation
X-Routing-Service
X-VWS-Id
X-Tumblr-Pixel-2
X-DataDome
X-Reqid
X-Varnish-Age
X-SRV
X-Proxied
X-LJ-Flow-ID
TWC-Locale-Group
X-AWS-Id
TWC-GeoIP-LatLong
X-Cloudmap
Webcakes-Region
Webcakes-App-Version
TWC-Privacy
Webcakes-App-Name
X-Git-Commit
TWC-GeoIP-Country
X-Cluster
TWC-Device-Class
ServedBy
TWC-Connection-Speed
X-Extlb
X-Container-Uri
X-Site-Version
X-R9-Blue-Green-Version
X-Served-From
X-Cache-Debug
X-Cms-Context
Mn-Server-Ip
Url
X-Webstats-RespID
X-Tncms
X-Skip-Cache
X-Redis-Cache
X-Cache-Status-Check
X-Labrador-Cache-Channel
X-Locale
X-Generated-By
X-IPLB-Request-ID
X-HTML-Minification-Powered-By
X-IPLB-Instance
X-Logging-Id
X-Loop
Apigw-Requestid
X-Restarts
Webserver
X-Accel-Version
X-Origin-Date
X-PHP-Host
Web-Mar-Node
Atl-Traceid
Frame-Options
WPO-Cache-Status
WPO-Cache-Message
X-Soup
X-Scope-Id
X-Proxy-Build
X-Tb
X-Upstream-Ht
X-Varnish-Beresp-Grace
X-Origin
X-Upstream-Ct
X-Timing-Wait
X-Forwarded-Host
X-Cache-Host
X-Akamai-Edgescape
Selected-Fe
X-Director
X-Fetched-On
X-Varnish-Cache-Hits
X-Format
X-Frame-Option
X-Web-Node
X-Ms-Version
X-Ms-Request-Id
X-Is-Tablet
X-ProxyCache-Key
X-ProxyCache-Status
X-Tcp-Rtt
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Is-Supported-Browser
X-Is-Mobile
X-Alternate-Cache-Key
X-Adobe-Source
Section-Io-Id
X-Browser-Name
X-BYPASS-REASON
X-Is-Desktop
X-Geo-Region
X-VCT
X-Httpd
Access-Control-Request-Headers
Cache-Hits
X-S
X-Azure-Ref-OriginShield
X-Detected-As
X-SayCDN-TTL
X-Say-Cacheable
X-Say-TTL
X-Sorting-Hat-ShopId
X-Origin-CC
X-Sorting-Hat-PodId
X-Origin-TTL
X-Optimistic-Header
LB
Xserver
X-Ismobilevalue
X-Api-Version
X-ShopId
X-Drupal-Cache-Tags
X-ShardId
X-Drupal-Cache-Contexts
X-Generation-Time
X-Request-URI
X-GeoCountry
X-CDN-Forward
X-GeoCode
X-Lagoon
Thinkindot-CacheControl
X-CMSURLCustom
X-Shield-Cache-Expires
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Thinkindot-L3
X-Vcache
TDXMobile
Source
Onion-Location
X-WP-CF-Super-Cache-Cookies-Bypass
X-TA-CDN-Provider
Protected
X-Cdn-Origin
X-Buckets
Expiry
X-Connection-Hash
X-Fastly-Request-Id
X-B3-Traceid
Cdn-Requestid
X-Tt-Logid
X-Fastcgi-Cache
AMP-Access-Control-Allow-Source-Origin
Fastcgi-Useragent
X-Worker
X-Vercel-Cache
X-Vercel-Id
X-Rocket-Nginx-Serving-Static
Azure-SiteName
X-Pass-Why
Azure-Version
Azure-SlotName
Azure-RegionName
X-Vcl-Version
Azure-InstanceId
X-PHP-Backend
X-Cache-Expired-At
Node
X-App-Version
CDN-Cache
CDN-EdgeStorageId
CDN-PullZone
X-ECache
Sid
CDN-RequestCountryCode
X-ID
CDN-CachedAt
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
Cross-Origin-Embedder-Policy
X-Cache-Action
X-Mg-Request-UUID
Priority
X-Aspnetmvc-Version
Environment
X-GEO
X-Proxy-Cache-Status
Uber-Trace-Id
X-Tumblr-Pixel-3
X-XRDS-Location
X-Cluster-Node
X-Server-W
Locale
X-Cache-Server
X-Urbn-Context-Path
X-Urbn-Site-Id
DB-Nickname
Alternate-Protocol
HostName
Cache-Tv-Group
X-FB-TRIP-ID
CF-IPCountry
User-Cache-Control
X-Jobs
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
X-Auth-Group-Type
X-Nf-Request-Id
X-Client-Ip
Sslversion
Gannett-Cam-Experience-Id
X-ND-Cache
X-Ig-Push-State
X-Esi-Check
X-Ec-Fail
X-Viewer-Country
X-Level-Front-Cache
A
X-Ec-GeoHdr
X-AIR-PT
T-Server
X-ScT
X-Vtex-Remote-Cache
X-Epic-Correlation-Id
Surrogated-Key
Rendered-Blocks
Meta-Geo-Continent
Ngx.Var.Host
X-Hnp-Log
X-Service
MD5-Digest
X-Gzip
Magicmarker
Odigeo-Trace-Id
Origin
Lang
X-Rojux
X-SB
X-Gen-Mode
X-Generated-On
Origin-Agent-Cluster
X-Ig-Origin-Region
X-Fastly-Backend
X-Dispatcher-Server
X-Dc
X-Bc-Bl
X-BCube-Filmed-By
X-Content-Age
DCR-Decision-By
X-D
X-TIM-N
DCR-Processing-Time-Ms
X-Bl-Debug
X-Block-Status
X-Cache-Id
X-NCache
X-Cache-NE
Content-Secure-Policy
X-SRCache-Key
X-Conf
Candidate-Md5Url
X-V-Cache
X-Custom-Header
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A
Wxu-Next-Region
Wxu-Next-Commit
X-Vdms-Version
Wxu-Next-Hostname
X-Op-Id-All
X-A-Dgt
X-Developer
X-Aed
X-Org
X-A-Wwc
Edge-Cache
X-Tx-Id
X-MP-GENERATED-AT
Fastly-Backend-Name
Content-Style-Type
X-Men
Content-Script-Type
Fastly-SSL
Host-ID
X-Mvc-Supplant-Cachable
X-HN
X-HS-Content-Campaign-Id
Server-Host
X-Debug-Cache-Fetch
X-Amz-Storage-Class
X-Debug-Cache-Store
X-Device-Os
Vix-Hermes-Req-Id
X-Cache-TTL-Remaining
X-App-Name
X-Auto-Login
X-Cdn-Srv
X-Cache-Info
X-Cache-Bucket
X-Clientip
X-Backend-Instance
X-Bip
V-Age
Ssr
X-Geo-Header
PFcat
X-GeoIP-City
X-GeoIP-Country-Code
X-GeoIP-Region-Code
NM-Fastcgi-Cache
X-Gdpr
X-Forwarded-Site
Server-Hostname
Sever-Int
Server-Ext
X-Fastly-Cache
X-FC-Vary-Parameters
Req-ID
X-GoCache-CacheStatus
C-Via
X-Wikidot-Backend
X-Wikidot-Static-Cache
XM
X-Edge-Server
X-VTEX-Cache-Time
X-Pad
X-VTEX-Cache-Server
Cdn-Host
X-Nginx-Cache-Key
X-Region-Sid
X-RateLimit-Remaining-Second
X-Request-Time
Country-Code
X-Core-Value
X-Scheme
X-Via-Fastly
X-VG-WebCache
X-Tec-Api-Root
X-Server-IP
X-Tec-Api-Version
X-Tec-Api-Origin
X-Thanos
X-Req
X-Test
X-UA-Device-Type
X-Varnish-Director
X-SD-PageType
X-CacheTTL
X-LSADC-Cache
X-VarnishDD-TTL
X-Varnish-Hostname
X-Fmm-Version
X-RateLimit-Limit-Second
Cdn-Request-Time
Cache-Provider
X-Origin-Expires
X-Platform
X-Node-Id
X-Policy
CDCHOST
X-Nyt-Route
X-Proto
X-Pubstack
X-Origin-Time
AKAMAI
X-PAYTM-SRV-ID
X-Origin-Response-Time
X-Powered-By-VTEX-Cache
X-NMSegId
Mime-Version
X-Varnish-Beresp-Ttl
X-DC
X-HITS
X-Location
X-Loc
X-Micro-Cache
X-Varnish-Beresp-Status
X-Date
X-Var-Ttl
X-Csrf-Jwt
X-NodeID
X-CGP
X-Mly-Id
X-SVT-ORM-RULES
X-From
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-Tb-Optimization-Total-Bytes-Saved
X-Slack-Backend
X-Varnish-CookieHashed-On
X-Up
X-Mvc-Supplant-OutputCached
X-Slack-Shared-Secret-Outcome
X-CUA
X-VG-TLSProxy
Tube-Got-Results
Esi-Enabled
X-Proxied-Request
Click-Count-Error
Click-Count-Action-Start
X-DefElseHash
X-DefHash
X-Request-Start
RNT-Time
Tube-Got-Eval
X-Request-Host
X-GeoIP
Req-Svc-Chain
RNT-Machine
Tube-Return
X-WA-Info
X-BBC-Edge-Cache-Status
X-Jungle-Id
Tube-Get-Contents
X-Varnishpool
X-Varnish-Remaining-TTL
X-Section
X-Ec-Custom-Error
X-Human
X-Acquia-Purge-Cdn-Unconfigured
X-Eu-Site
X-Hash
X-Pool
X-B3-Trace-ID
X-We-Are-Hiring
X-Varnish-CookieINHashed-On
Web-Mar-Region
X-LiteSpeed-Cache-Control
HA-Ipaddr
L
Ha-Gx-Prefs
W
X-Access
X-Accel-Expires-Debug
We-Hiring
L5d-Success-Class
Machine
Proxy-Firewall
Pramga
Powered-By
Origin-CC
On-Server
Mail-Subject
Release
Origin-EX
Gh-Request-Id
Apple-News-Services-Request-Url
Cache-Key
Canary
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Cache-Backend
Fastly-GeoIP-CountryCode
Cdncip
X-Aicache-OS
X-AK-Request-ID
DSUID
Cluster
Cdnsip
X-Zone
X-Vdms-Path
Yak-Timeinfo
X-Varnish-Authentication
Adler-Geo
Producers
True-Client-Country-4JS
X-DPWN-IS-SECURE
X-Ad-Load-Variation
X-Depends
X-Cache-Aspx
Platform
NGX
X-Contensis-Viewer-Groups
Is-Eu
X-Cs
CDN-RequestId
X-Uri
X-LB-ID
WP-Super-Cache
Debug
X-Newrelic-Synthetics
Redirect-Candidate
X-NGINX-Cache
X-Varnish-Hits
X-CACHE-GROUP
X-Cache-FS-Status
X-Akamai-Transformed
X-PERF
X-Via-Popv
X-Via-Poph
X-HA-Backend
X-Refresh
X-ApacheServer
X-Via-Popn
X-Datadome
X-Render-Time
Pics-Label
X-VHOST
Server-Info
CloudFront-Viewer-Country
X-Original-Request-Id
X-Nananana
X-Response-Served-From
Fastly-Drupal-HTML
SID
X-M-Log
X-M-Reqid
BehaviorPad-Version
X-VC-TTL
X-Servedbyhost
X-Parent-Response-Time
X-TT-LOGID
X-LB-NoCache
X-CACHE-AGE
X-APP
Fastly-Drupal-Html
Locid
GeoIP-Latitude
X-Cached-By
X-B3-Parentspanid
Datacenter
X-DynaTrace-JS-Agent
X-Litespeed-Tag
X-CDN-Cache-Status
Server-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Amz-Meta-Cb-Modifiedtime
X-VCache
X-Content-Length
Cf-Ipcountry
X-CS
GeoIp-Country-Code
Resin-Trace
X-LiteSpeed-Tag
X-IAuth-Set-Uid
Cdn
X-Nc
X-Wa
Ngx-Var-Key
NtCoent-Length
X-Old-Content-Length
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
Uri
FSS-Cache
X-ZONE
X-Vgn-Hpd-Reason
X-TX-ID
X-NewRelic-App-Data
X-Varnish-Beresp-TTL
Tcn
X-Fpc
True-Client-Ip
X-Esi
X-Moov-T
X-Dispatcher-Number
X-TH-Server
X-Moov-Xdn-Version
X-SERVER-NAME
Vc-Max-Age
X-HostName
CDN
X-Srv
Product
Serverhost
X-RequestId
True-Client-IP
Cross-Origin-Embedder-Policy-Report-Only
X-TIME
X-Oracle-DMS-ECID
X-Cdn-Forward
S-Rt
X-User
X-B3-Spanid
X-Destination
X-Application
X-B-Cookie
X-FPC
X-Ckpd-Fst-Backend
X-External-Request-Id
X-S-Cookie
GeoIP-Country-Code
X-Dynatrace-Js-Agent
Cf-Device-Type
Srv
Request-ID
X-Nf-Country
X-Nf-Language
X-Zen-Fury
X-Nf-Ats-Version
X-NC
X-Dispatch
X-Cdn-Cache-Status
X-WA
ServerName
X-Vc
X-CACHE-KEY
X-Cache-Date
Geoip-Latitude
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
CacheControlHeader
X-Bug-Bounty
X-Instance-Name
Server-Id
X-APP-VERSION
X-Geo
X-COUNTRY
X-HubSpot-Correlation-Id
Hostname
X-Webkit-Csp-Report-Only
X-VServer
Ohc-File-Size
X-FL-QIT-DEBUG
X-API-Version
Srvid
X-Presslabs-Stats
X-Branch-Name
X-Correlation-ID
X-Lb-Nocache
X-Segment-20210421
X-Via-PopV
X-Ha-Backend
X-ServedByHost
User-Agent
Load-Balancing
DataCenter
Origin-Trial
X-Via-PopH
X-Via-PopN
X-DynaTrace
X-VCL-Version
X-Gamma-Serve
X-DataCenter
ServerHost
X-Akamai-Device-Characteristics
X-Info
Epwk-X-Cache
X-Vmg-Version
Cloudfront-Viewer-Country
Lb
X-Cache-Ttl
X-App
Cneonction
Type
X-Ua
PICS-Label
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Rtss
Xc-Version
Expect-Staple
X-Owner
X-MiniProfiler-Ids
Ohc-Cache-HIT
X-Limited
X-Irp-Debug
Cross-Origin-Opener-Policy-Report-Only
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Sqd-Ctime
X-Qloud-Router
X-Sqd-Stime
Sm-Log-Id
Edge-Copy-Time
Warning
Cl-Cache
X-Core-Mission
X-Service-Response-Time
X-Check-Cacheable
X-Aspnet-Duration-Ms
X-Amz-Meta-Opti
X-Via-SSL
X-Via-Edge
X-Flags
X-Is-Crawler
X-Web-Server
X-Route-Name
X-Providence-Cookie
X-Via-CDN
X-Datacenter
X-Acquia-Application-Trace
X-Serial
Cmstype
X-Lb-Id
Timeexpire
X-MSEdge-Features
X-MSEdge-Flight
X-Akamai-Pragma-Client-IP
Cmsid
CountryCode
X-Litespeed-Cache-Control
Servername
X-Page-View
X-LAGOON
X-CSRF-TOKEN
X-Th-Server
X-Sql-Duration-Ms
X-Origin-Upstream-Status
X-RAMCache
X-Requestid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Shardid
X-Shopid
X-Sql-Count
X-Snapshot-Date
X-IN-APIGATEWAY
X-Dw-Trace-Id
X-Amz-Meta-S3b-Last-Modified
X-Amz-Meta-Sha256
X-IN-APIGATEWAYSSL
IsBot
X-Ramcache
X-Udemy-Cache-App-Namespace
Ngx
X-Http-Reason
X-SIPLIST1