Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
X-XSS-Protection
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-AspNet-Version
X-Runtime
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Envoy-Upstream-Service-Time
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
CF-Ray
Access-Control-Max-Age
Expect-Ct
X-Amz-Request-Id
X-Amz-Id-2
X-Via
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
P3p
X-Cache-Group
X-UA-Device
Permissions-Policy
X-Robots-Tag
X-AH-Environment
X-Server
X-Hacker
X-Proxy-Cache
X-Turbo-Charged-By
Xkey
X-Rq
X-Ws-Request-Id
X-Age
X-Vhost
X-Amz-Version-Id
Cf-Apo-Via
X-Dispatcher
X-Swift-SaveTime
X-Swift-CacheTime
Allow
X-Server-Powered-By
X-LiteSpeed-Cache
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Page-Speed
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
Cf-Railgun
EagleEye-TraceId
X-Host
X-WebKit-CSP
X-Backend-Server
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Dns-Prefetch-Control
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
X-Ruxit-JS-Agent
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Application-Context
X-Nginx-Cache-Status
X-Country
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-Country-Code
Service-Worker-Allowed
X-Content-Type
X-Trace
X-Url
Cache-Tag
X-Litespeed-Cache
X-Clacks-Overhead
Rating
X-CST
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-Times
X-Vname
X-PC
X-TtlSet
X-FTR-Request-ID
X-Daa-Tunnel
Nginx-Cache
Cross-Origin-Opener-Policy
X-Server-Name
X-Edge
X-Mcache
X-Browser-Type
X-Midtier
X-Powered-By-Plesk
X-Oneagent-Js-Injection
X-Cnection
X-ESI
X-Webkit-Csp
AR-Request-ID
AR-ATIME
AR-SID
AR-PoweredBy
X-GitHub-Request-Id
X-Element-Page-Cache
X-D2id
Edge-Control
X-Ac
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
Verso
X-MS-InvokeApp
X-Upstream
X-ECACHE
X-Cache-TTL
X-FastCGI-Cache
X-Vcap-Request-Id
AR-CACHE
X-Abt-Application-Version
X-Ser
X-Navigation-Version
X-Dw-Request-Base-Id
SPIisLatency
SPRequestDuration
X-Mod-Pagespeed
Fastly-Restarts
X-NF-Request-ID
X-SharePointHealthScore
SPRequestGuid
X-Amz-Rid
X-B3-TraceId
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Client-IP
X-Edge-Location-Klb
X-Kinsta-Cache
X-Mg-S
Edge-Cache-Tag
X-Goog-Hash
X-Middleton-Display
X-Sol
Display
Pagespeed
S
X-Powered-CMS
X-ARC
X-Ratelimit-Limit
Cache-Status
X-Amzn-Trace-Id
Access-Control-Request-Method
X-Version
X-Middleton-Response
Response
X-Ruxit-Js-Agent
X-VARITI-CCR
X-PDP-UNCACHING-HASH
X-Cache-Key
X-Fastly-Request-ID
X-Content-Digest
X-TraceId
RTSS
Cross-Origin-Resource-Policy
X-T
Realpath
X-Forwarded-For
X-Ratelimit-Remaining
X-TTL
X-Recruiting
X-Correlation-Id
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Cached
X-RateLimit-Remaining
Front-End-Https
X-MSEdge-Ref
MS-Author-Via
X-Shield-Request-Id
Content-MD5
X-Protected-By
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Ua-Browser
X-Forwarded-Proto
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-Aws-Lambda-Call-Status
X-FTR-Backend-Server
X-FTR-Balancer
Public-Key-Pins
X-Request-Received
X-Request-Processing-Time
X-Frontend
Server-Node
Payment
TP-Cache
MicrosoftSharePointTeamServices
X-LLID
X-PressLabs-Stats
X-HS-Combine-CSS
X-SRCache-Store-Status
Arr-Disable-Session-Affinity
X-SRCache-Fetch-Status
X-FTR-Expires
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Server-ID
X-Distributor
X-Varnish-TTL
Count-Hit
X-Accel-Expires
X-GUploader-UploadID
X-Origin-Server
X-NODE
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-LB-Cache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Ezoic-Cdn
Accept-Ch
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Request-Handler-Origin-Region
X-Microsite
X-Az
X-AppVersion
X-Activity-Id
X-ORACLE-DMS-ECID
X-Cluster-Name
Host
X-Varnish-Server
X-App-Server
X-Varnish-Backend
Cache-Tags
X-Ua-Device
X-Www-Served-By
X-B3-TraceId-Primal
Accept-Charset
X-Newrelic-App-Data
Retry-After
MRF-Tech
Mrf-Cache-Status
X-Amz-Meta-S3cmd-Attrs
X-Content-Security-Policy-Report-Only
Cleartype
Server-Name
X-Ttl
X-Goog-Metageneration
X-ASPNET-VERSION
X-Hits
X-Envoy-Decorator-Operation
Filterid
X-Varnish-Ttl
X-Unique-Id
X-CSRF-Token
X-Git-Hash
X-Hostname
Access-Control-Allow-Method
X-Azure-Ref
Referer-Policy
X-Upgrade-Enabled
X-Geo-Country
X-Load-Cache
X-NGENIX-Cache
TP-L2-Cache
X-Seen-By
X-Tt-Trace-Host
X-Tt-Trace-Tag
TCN
X-Logged-In
X-Id
X-Debug
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Proxy
X-CCDN-CacheTTL
X-Time
X-FB-Debug
X-B3-Sampled
X-XRDS-LOCATION
X-F-Cache
X-Grace
DC
X-Trace-Id
X-Amz-Apigw-Id
Section-Io-Cache
X-B
X-Revision
X-Request-Guid
X-Amzn-RequestId
X-TT
X-DIS-Request-ID
X-Cache-Control
X-Type
Healthy
X-Fb-Rlafr
X-Contextid
Viewport
Paypal-Debug-Id
X-Mobile
Surrogate-Key
X-N
X-WP-CF-Super-Cache-Cache-Control
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Debug-Info
X-Goog-Stored-Content-Length
X-WP-CF-Super-Cache
X-Goog-Generation
Fastly-SWR
X-Page-Id
Fastly-SIE
X-Px
Content-Disposition
X-Whom
X-Webkit-CSP
X-Via-JSL
Version
X-Origin-Cache
X-Varnish-Grace
X-Datadog-Trace-Id
X-Content-Options
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
Charset
X-Magnolia-Registration
X-Template
X-Oracle-Dms-Ecid
X-Cache-Grace
X-Wix-Request-Id
X-Cache-Age
X-Amz-Replication-Status
X-Rid
X-RemovedCookies
X-ProcessESI
X-App-Environment
X-Tumblr-Pixel
X-RTag
X-Node-Name
X-Tumblr-Pixel-0
X-Rule
X-Tumblr-Pixel-1
X-UUID
Ms-Operation-Id
MS-CV
X-Tumblr-User
X-Datadog-Sampled
X-Source
X-Signature
X-Debug-IsConnected
X-Debug-IsPreview
X-B-Cache
X-Hl-Ver
X-G
X-EdgeConnect-Cache-Status
SD-X-WS
X-Yottaa-Metrics
X-Yottaa-Optimizations
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-FW-Static
X-FW-Server
X-FW-Hash
X-FW-Serve
X-Environment-Context
X-Cacheable-TTL
SRV
ServerID
X-Backend-Name
X-FW-Dynamic
X-Instance
X-Region
X-FW-Type
X-User-Agent
X-Adobe-Content
X-Adobe-Loc
X-L-Path
X-NWS-UUID-VERIFY
X-Storage
X-FW-Version
X-ServerID
GEO-INFO
X-Status
X-Proxy-Cache-Info
X-Is-Bot
X-NYM-Debug-Backend
Country
X-Cache-Hit
X-Language
X-Device-Type
X-Real-IP
X-Rendered-As
NGB
X-IPS-LoggedIn
Countrycode
Cross-Origin-Window-Policy
Liferay-Portal
X-Amzn-Remapped-Content-Length
Akamai-GRN
X-Origin-Cache-Key
X-B3-SpanId
X-Sucuri-ID
X-WP-CF-Super-Cache-Active
X-Sucuri-Cache
X-RM-Cache-TTL
Front
X-Wormhole-Sdk
OT-Force-Account-Verify
X-Oracle-Dms-Rid
X-Framework
X-Servername
X-Ratelimit-Reset
X-UA
From-Origin
X-Air-Pt
X-RateLimit-Limit
X-VC-Cache
X-AB
X-VC
X-WebKit-CSP-Report-Only
X-Mode
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
Amp-Access-Control-Allow-Source-Origin
Xet-Cookie
Backend
X-Content-Powered-By
X-Akamai-Request-ID2
Upgrade-Insecure-Requests
X-Nginx-Cache
X-Xrds-Location
X-URL
Refresh
X-INCAP-ABP
X-Cache-Time
X-Handled-By
X-B3-Traceid
X-Edge-Location
Accept-Language
X-Endurance-Cache-Level
X-Xfnlog-Site
X-JoinUs
X-SaId
X-Rn-Rsrv
X-RCS-CacheZone
X-Rewrite-Enabled
X-UPSTREAM-Address
Meta-Geo
Cache
X-RateLimit-Reset
Filters
X-Webstats-RespID
X-Varnish-Age
X-Lambda-Id
X-LJ-Flow-ID
X-No-Session
Property-Id
X-Cache-Operation
X-Cache-Rule
X-Tumblr-Pixel-2
X-PHP-Host
X-Hosted-By
X-Git-Commit
TWC-Privacy
Webcakes-Region
X-Labrador-Cache-Channel
X-Reqid
X-Generated-By
X-Proxied
X-Zipkin-Id
X-VWS-Id
Webcakes-App-Name
X-Container-Uri
X-Extlb
X-Cluster
X-AWS-Id
X-Routing-Service
TWC-Device-Class
X-Origin-Date
TWC-Connection-Speed
ServedBy
X-DataDome
TWC-GeoIP-Country
TWC-Locale-Group
X-Provided-By
TWC-GeoIP-LatLong
X-Cloudmap
X-Origin-Hint
Webcakes-App-Version
X-Tb
X-Cache-Status-Check
Webserver
Atl-Traceid
X-Akamai-Edgescape
X-Logging-Id
X-Scope-Id
X-Loop
X-Cache-Debug
X-Tncms
X-Adobe-Source
X-Skip-Cache
X-Locale
X-Web-Node
X-Site-Version
X-Served-From
X-Cms-Context
X-R9-Blue-Green-Version
X-Accel-Version
X-Fetched-On
Web-Mar-Node
Url
Section-Io-Id
X-Forwarded-Host
X-Redis-Cache
X-IPLB-Request-ID
X-IPLB-Instance
X-HTML-Minification-Powered-By
X-Restarts
Mn-Server-Ip
Apigw-Requestid
Frame-Options
WPO-Cache-Status
WPO-Cache-Message
X-Is-Tablet
X-Is-Supported-Browser
X-Cache-Host
X-BYPASS-REASON
X-Alternate-Cache-Key
X-Azure-Ref-OriginShield
X-Browser-Name
X-Tcp-Rtt
X-Ms-Request-Id
Selected-Fe
X-Format
X-Httpd
X-Is-Desktop
X-Geo-Region
X-Frame-Option
X-Is-Mobile
X-Director
Access-Control-Request-Headers
X-Origin
X-VCT
X-Timing-Wait
X-ProxyCache-Status
X-Upstream-Ct
X-Upstream-Ht
X-Varnish-Beresp-Grace
X-Varnish-Cache-Hits
X-Soup
X-Shopify-Stage
X-Proxy-Build
X-Storefront-Renderer-Rendered
X-ProxyCache-Key
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-Ms-Version
X-SRV
Cache-Hits
X-S
X-GeoCountry
X-RID
Xserver
X-GeoCode
X-Detected-As
X-Api-Version
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
LB
X-Drupal-Cache-Tags
X-Sorting-Hat-ShopId
X-Origin-TTL
X-Origin-CC
X-Optimistic-Header
X-Ismobilevalue
X-Thinkindot-L3
X-Shield-Cache-Expires
X-Generation-Time
X-Drupal-Cache-Contexts
X-CMSURLCustom
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
TDXMobile
X-Request-URI
X-CDN-Forward
X-Lagoon
Source
X-Cdn-Origin
X-Vcache
Fastcgi-Useragent
Onion-Location
Protected
X-WP-CF-Super-Cache-Cookies-Bypass
X-Fastly-Request-Id
X-Connection-Hash
Expiry
X-TA-CDN-Provider
X-Buckets
X-Tt-Logid
X-Vercel-Id
X-Worker
Cdn-Requestid
X-Vercel-Cache
AMP-Access-Control-Allow-Source-Origin
Azure-InstanceId
X-Rocket-Nginx-Serving-Static
X-Pass-Why
X-Cache-Expired-At
X-PHP-Backend
Azure-SlotName
Azure-Version
Azure-SiteName
X-Vcl-Version
Azure-RegionName
Node
X-Mg-Request-UUID
X-App-Version
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-PullZone
X-ECache
Sid
CDN-RequestPullSuccess
CDN-Cache
CDN-CachedAt
X-ID
CDN-Uid
Cross-Origin-Embedder-Policy
X-Cache-Action
Priority
X-Aspnetmvc-Version
Environment
X-GEO
Uber-Trace-Id
X-Tumblr-Pixel-3
X-Proxy-Cache-Status
X-XRDS-Location
X-Cluster-Node
X-Server-W
Locale
X-Urbn-Site-Id
X-Cache-Server
X-Urbn-Context-Path
X-Fastcgi-Cache
DB-Nickname
Cache-Tv-Group
Alternate-Protocol
HostName
CF-IPCountry
X-Jobs
X-FB-TRIP-ID
User-Cache-Control
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
X-Auth-Group-Type
Fusion-Content-Id
X-Client-Ip
X-Nf-Request-Id
X-Service
A
Wxu-Next-Hostname
X-Generated-On
X-Gen-Mode
X-Fastly-Backend
X-GeoIP-City
X-Gzip
X-Ig-Origin-Region
X-Hnp-Log
X-Esi-Check
X-Epic-Correlation-Id
X-Developer
X-D
X-Device-Os
X-Dispatcher-Server
X-Ec-GeoHdr
X-Ec-Fail
X-Ig-Push-State
X-Level-Front-Cache
X-UA-Device-Type
X-TIM-N
X-SRCache-Key
X-V-Cache
X-Vdms-Version
X-Vtex-Remote-Cache
X-Viewer-Country
X-ScT
X-SB
X-ND-Cache
X-NCache
X-Op-Id-All
X-Org
X-Rojux
X-Origin-Expires
X-Custom-Header
X-Content-Age
Odigeo-Trace-Id
Ngx.Var.Host
Meta-Geo-Continent
Origin
Origin-Agent-Cluster
Sslversion
Rendered-Blocks
MD5-Digest
Magicmarker
DCR-Decision-By
Content-Secure-Policy
DCR-Processing-Time-Ms
Edge-Cache
Lang
Gannett-Cam-Experience-Id
Surrogated-Key
T-Server
X-Bl-Debug
X-BCube-Filmed-By
X-Bc-Bl
X-Block-Status
X-Cache-Id
X-Conf
X-Cache-NE
X-Aed
X-A-Wwc
X-A
Wxu-Next-Commit
X-A-Ccd
X-A-Dam
X-A-Dgt
X-A-Dcw
Candidate-Md5Url
Wxu-Next-Region
X-LSADC-Cache
X-Dc
X-MP-GENERATED-AT
X-Pad
X-Tx-Id
Powered-By
Origin-EX
X-Forwarded-Site
Origin-CC
PFcat
X-FC-Vary-Parameters
X-VTEX-Cache-Server
Server-Ext
X-Edge-Server
Req-ID
X-Fmm-Version
X-Fastly-Cache
X-VG-WebCache
X-Tec-Api-Root
X-Cache-Bucket
X-Tec-Api-Origin
X-HN
X-Req
X-VarnishDD-TTL
X-GoCache-CacheStatus
X-GeoIP-Region-Code
X-Geo-Header
Server-Host
X-GeoIP
X-GeoIP-Country-Code
NM-Fastcgi-Cache
X-Gdpr
Sever-Int
X-App-Name
X-Auto-Login
Cdn-Request-Time
X-Amz-Storage-Class
X-SD-PageType
X-AK-Request-ID
X-Clientip
X-Backend-Instance
X-CacheTTL
X-Cache-Info
Country-Code
X-Bip
X-Cdn-Srv
Cdn-Host
X-Debug-Cache-Fetch
X-Core-Value
X-Cache-TTL-Remaining
Ssr
X-DefElseHash
X-DefHash
Host-ID
X-VTEX-Cache-Time
V-Age
XM
X-Debug-Cache-Store
X-Wikidot-Static-Cache
X-Wikidot-Backend
Vix-Hermes-Req-Id
Server-Hostname
X-Tec-Api-Version
X-Tb-Optimization-Total-Bytes-Saved
AKAMAI
X-SVT-ORM-VERSION
X-HS-Content-Campaign-Id
X-Origin-Response-Time
X-Nyt-Route
X-Node-Id
X-Test
Cache-Provider
C-Via
X-Nginx-Cache-Key
X-NMSegId
X-Origin-Time
X-Sn-Servicetimems
X-Region-Sid
X-RateLimit-Remaining-Second
X-Request-Time
X-Server-IP
X-Scheme
X-RateLimit-Limit-Second
X-Pubstack
X-Platform
X-PAYTM-SRV-ID
X-Policy
X-Powered-By-VTEX-Cache
X-Proto
X-Mvc-Supplant-Cachable
X-SVT-ORM-RULES
X-Varnish-Remaining-TTL
X-Loc
Content-Style-Type
X-Varnish-CookieHashed-On
Fastly-SSL
Fastly-Backend-Name
X-Varnish-Director
X-Varnish-CookieINHashed-On
X-Via-Fastly
X-Varnish-Hostname
X-Thanos
Content-Script-Type
Cdncip
X-Men
CDCHOST
Cdnsip
X-Varnish-Beresp-Ttl
X-HITS
X-DC
Mime-Version
X-Contensis-Viewer-Groups
Click-Count-Action-Start
X-Csrf-Jwt
X-Request-Host
X-Hash
X-Human
Esi-Enabled
Is-Eu
X-Section
X-Slack-Backend
X-Request-Start
X-CGP
Click-Count-Error
X-Depends
X-Varnish-Authentication
X-Ec-Custom-Error
Yak-Timeinfo
X-Jungle-Id
X-Var-Ttl
X-Location
X-Eu-Site
X-We-Are-Hiring
Adler-Geo
X-Pool
X-Varnishpool
X-LiteSpeed-Cache-Control
X-CUA
X-Date
X-Proxied-Request
X-Mvc-Supplant-OutputCached
X-Varnish-Beresp-Status
X-Slack-Shared-Secret-Outcome
X-Aicache-OS
X-Mly-Id
X-Micro-Cache
X-NodeID
Mail-Subject
X-Cache-Backend
Machine
On-Server
X-From
True-Client-Country-4JS
X-BBC-Edge-Cache-Status
X-DPWN-IS-SECURE
Release
Pramga
Proxy-Firewall
L
HA-Ipaddr
Cache-Key
Canary
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
X-WA-Info
Cluster
Gh-Request-Id
Ha-Gx-Prefs
X-Up
Fastly-GeoIP-CountryCode
X-VG-TLSProxy
DSUID
X-B3-Trace-ID
L5d-Success-Class
Producers
Tube-Got-Eval
Platform
RNT-Machine
X-Accel-Expires-Debug
X-Access
RNT-Time
Tube-Get-Contents
Req-Svc-Chain
Tube-Got-Results
X-Ad-Load-Variation
We-Hiring
X-Acquia-Purge-Cdn-Unconfigured
Web-Mar-Region
W
X-Cache-Aspx
Tube-Return
X-Zone
X-AIR-PT
X-Vdms-Path
NGX
CDN-RequestId
X-Cs
X-Uri
WP-Super-Cache
Debug
X-LB-ID
X-Newrelic-Synthetics
Redirect-Candidate
X-Varnish-Hits
X-Cache-FS-Status
X-CACHE-GROUP
X-NGINX-Cache
X-Akamai-Transformed
X-Datadome
X-Via-Poph
X-PERF
Fastly-Drupal-HTML
Pics-Label
X-Via-Popn
X-Refresh
X-ApacheServer
X-Via-Popv
X-Render-Time
CloudFront-Viewer-Country
X-HA-Backend
X-VHOST
X-Original-Request-Id
X-Nananana
X-Servedbyhost
Server-Info
X-Response-Served-From
SID
X-M-Reqid
BehaviorPad-Version
X-M-Log
X-VC-TTL
X-Parent-Response-Time
X-TT-LOGID
X-B3-Parentspanid
X-LB-NoCache
X-CACHE-AGE
X-APP
Locid
GeoIP-Latitude
Fastly-Drupal-Html
Datacenter
X-Cached-By
X-DynaTrace-JS-Agent
X-Litespeed-Tag
X-Content-Length
Server-ID
X-VCache
X-Amz-Meta-Cb-Modifiedtime
X-CDN-Cache-Status
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Cf-Ipcountry
X-CS
X-Nc
Cdn
Resin-Trace
X-LiteSpeed-Tag
GeoIp-Country-Code
X-Wa
X-IAuth-Set-Uid
X-Old-Content-Length
NtCoent-Length
Ngx-Var-Key
X-Platform-Cluster
X-Platform-Router
X-Platform-Processor
X-Vgn-Hpd-Reason
Uri
FSS-Cache
X-TX-ID
X-Fpc
X-ZONE
X-Srv
X-NewRelic-App-Data
X-Varnish-Beresp-TTL
Vc-Max-Age
X-RequestId
X-Dispatcher-Number
Serverhost
X-Esi
X-Moov-Xdn-Version
X-TH-Server
X-Moov-T
True-Client-Ip
CDN
X-B3-Spanid
X-SERVER-NAME
X-HostName
True-Client-IP
Product
Cross-Origin-Embedder-Policy-Report-Only
Tcn
X-Oracle-DMS-ECID
X-TIME
X-B-Cookie
Srv
X-S-Cookie
X-Application
X-Dynatrace-Js-Agent
X-Ckpd-Fst-Backend
S-Rt
X-User
X-Cdn-Forward
X-FPC
GeoIP-Country-Code
X-Destination
X-External-Request-Id
Cf-Device-Type
Request-ID
X-Nf-Language
X-Dispatch
ServerName
X-NC
X-Vc
X-Nf-Country
X-Cdn-Cache-Status
X-Zen-Fury
X-Nf-Ats-Version
X-Bug-Bounty
X-WA
X-CACHE-KEY
X-Rocket-Build-Number
X-Sigma
X-Cache-Date
X-Sigma-Backend
Server-Id
Geoip-Latitude
X-Instance-Name
CacheControlHeader
X-Geo
Hostname
X-COUNTRY
X-APP-VERSION
X-HubSpot-Correlation-Id
Srvid
Ohc-File-Size
X-FL-QIT-DEBUG
X-API-Version
X-VServer
X-Webkit-Csp-Report-Only
X-Presslabs-Stats
X-Branch-Name
X-Lb-Nocache
Rtss
X-Segment-20210421
X-ServedByHost
X-Via-PopV
X-Via-PopN
X-Via-PopH
DataCenter
Load-Balancing
Origin-Trial
X-Akamai-Device-Characteristics
User-Agent
X-Vmg-Version
X-Ha-Backend
X-VCL-Version
X-DynaTrace
Epwk-X-Cache
X-DataCenter
ServerHost
Cloudfront-Viewer-Country
X-Info
X-Gamma-Serve
X-Cache-Ttl
Lb
Xc-Version
Cneonction
X-Ua
X-App
PICS-Label
Type
X-Limited
X-Correlation-ID
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Expect-Staple
Cross-Origin-Opener-Policy-Report-Only
Ohc-Cache-HIT
X-Irp-Debug
X-MiniProfiler-Ids
X-Owner
X-MSEdge-Flight
X-Via-CDN
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Flags
Sm-Log-Id
X-Service-Response-Time
X-Acquia-Purge-Tags
X-Via-SSL
X-Is-Crawler
X-Sqd-Stime
X-Qloud-Router
X-Lb-Id
Timeexpire
X-Amz-Meta-Opti
Cmstype
Cmsid
X-Sqd-Ctime
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Route-Name
X-Acquia-Site
X-Via-Edge
X-Core-Mission
X-Datacenter
X-Check-Cacheable
X-Serial
X-Web-Server
Warning
X-MSEdge-Features
X-Akamai-Pragma-Client-IP
Edge-Copy-Time
Cl-Cache
Servername
CountryCode
X-Litespeed-Cache-Control
X-Page-View
X-CSRF-TOKEN
X-LAGOON
X-Sql-Count
X-Shopid
X-Sorting-Hat-Shopid
X-RAMCache
X-Sorting-Hat-Podid
X-Shardid
X-Origin-Upstream-Status
X-SIPLIST1
X-Ramcache
X-Udemy-Cache-App-Namespace
Ngx
X-Amz-Meta-Sha256
X-Amz-Meta-S3b-Last-Modified
IsBot
X-Requestid
X-Dw-Trace-Id
X-Http-Reason
X-Th-Server
X-Snapshot-Date
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Sql-Duration-Ms