Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Accept-CH
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH-Lifetime
X-Ua-Compatible
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Check
X-Cache-Status
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
CF-Ray
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Cf-Edge-Cache
Host-Header
EagleId
Keep-Alive
Request-Context
X-Backend
X-UA-Device
X-Cache-Group
X-AH-Environment
X-Robots-Tag
X-Server
X-Hacker
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Proxy-Cache
X-Ws-Request-Id
Xkey
X-Rq
X-Age
Permissions-Policy
X-Vhost
X-Amz-Version-Id
Allow
X-Dispatcher
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Powered-By
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
P3p
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Device
X-OneAgent-JS-Injection
Cf-Railgun
X-Backend-Server
EagleEye-TraceId
X-Host
X-Server-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-WebKit-CSP
X-Response-Time
X-Readtime
X-Akam-SW-Version
Surrogate-Control
X-HW
X-Litespeed-Cache
Request-Id
X-Cloud-Trace-Context
X-Node
Content-Location
X-Application-Context
X-Ruxit-JS-Agent
X-Nginx-Cache-Status
X-Nginx-Upstream-Cache-Status
X-CST
X-NWS-LOG-UUID
X-Country
Service-Worker-Allowed
X-Country-Code
X-Url
X-Content-Type
X-Clacks-Overhead
Cache-Tag
X-Trace
X-Oneagent-Js-Injection
X-Webkit-Csp
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Times
X-Server-Name
X-FTR-Request-ID
X-Vname
X-PC
X-TtlSet
X-Daa-Tunnel
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-Midtier
X-Browser-Type
X-Powered-By-Plesk
X-Cnection
X-ESI
X-Upstream
Edge-Control
X-MS-InvokeApp
X-GitHub-Request-Id
X-D2id
X-Element-Page-Cache
X-Ac
Verso
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-Aws-Lambda-Call-Status
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
X-ECACHE
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Ser
X-Vcap-Request-Id
X-Navigation-Version
X-Cache-TTL
X-Abt-Application-Version
X-Mod-Pagespeed
SPIisLatency
SPRequestDuration
AR-CACHE
X-Ruxit-Js-Agent
X-Dw-Request-Base-Id
X-NF-Request-ID
X-SharePointHealthScore
SPRequestGuid
X-B3-TraceId
X-Amz-Rid
Fastly-Restarts
X-Client-IP
X-Erf-Bev-Bev
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Middleton-Display
X-Sol
Display
Pagespeed
Edge-Cache-Tag
X-RateLimit-Remaining
X-Mg-S
S
X-Cache-Key
X-Edge-Location-Klb
X-Kinsta-Cache
X-Powered-CMS
X-Amzn-Trace-Id
Response
X-Middleton-Response
Cache-Status
X-VARITI-CCR
Access-Control-Request-Method
X-Version
X-Goog-Hash
X-ARC
RTSS
X-Content-Digest
X-Fastly-Request-ID
X-TraceId
X-Forwarded-For
X-Recruiting
Cross-Origin-Resource-Policy
X-T
X-Server-ID
Realpath
Pinterest-Generated-By
Pinterest-Version
X-Ttl
X-Pinterest-Rid
X-Correlation-Id
X-MSEdge-Ref
MS-Author-Via
Front-End-Https
Fastcgi-Cache
X-Cached
X-Varnish-TTL
Content-MD5
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Ua-Browser
X-Ratelimit-Limit
Server-Node
X-FTR-Cache-Status
X-Country-Code-Real
Payment
X-FTR-Balancer
X-Protected-By
X-FTR-Backend-Server
X-FTR-Backend
Public-Key-Pins
X-Request-Received
X-PDP-UNCACHING-HASH
Arr-Disable-Session-Affinity
X-Request-Processing-Time
X-LLID
X-Frontend
X-Forwarded-Proto
X-HS-Combine-CSS
MicrosoftSharePointTeamServices
X-Shield-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
TP-Cache
X-Origin-Cache-Key
X-Distributor
X-Accel-Expires
X-Jurisdiction
X-FTR-Expires
X-Kong-Proxy-Latency
X-HP-Webp
X-HP-Trace-Id
X-Kong-Upstream-Latency
Count-Hit
X-GUploader-UploadID
X-Hits
X-Origin-Server
X-LB-Cache
X-Ezoic-Cdn
X-ORACLE-DMS-RID
X-Microsite
X-Content-Security-Policy-Report-Only
X-Request-Handler-Origin-Region
X-Az
X-AppVersion
X-Activity-Id
X-PressLabs-Stats
Host
X-B3-TraceId-Primal
X-TEC-API-VERSION
X-Cluster-Name
X-Www-Served-By
X-Varnish-Backend
X-Ua-Device
MRF-Tech
X-TTL
X-TEC-API-ORIGIN
Mrf-Cache-Status
X-TEC-API-ROOT
Retry-After
X-Varnish-Server
Cache-Tags
X-Ratelimit-Remaining
X-App-Server
Accept-Charset
X-Amz-Meta-S3cmd-Attrs
X-Id
X-Hostname
Server-Name
X-NGENIX-Cache
X-Geo-Country
Cleartype
X-RateLimit-Limit
X-NODE
X-Envoy-Decorator-Operation
X-Newrelic-App-Data
Referer-Policy
X-DIS-Request-ID
X-Goog-Metageneration
X-Upgrade-Enabled
TP-L2-Cache
X-Seen-By
X-CSRF-Token
X-Amz-Apigw-Id
X-Git-Hash
Access-Control-Allow-Method
X-Oracle-Dms-Ecid
X-Amzn-RequestId
TCN
X-Azure-Ref
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-F-Cache
X-CCDN-Origin-Time
X-Load-Cache
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Proxy
X-Unique-Id
X-ORACLE-DMS-ECID
X-Grace
X-Px
Filterid
Healthy
X-Varnish-Ttl
X-Cache-Control
X-Debug-Info
X-Revision
Paypal-Debug-Id
X-Request-Guid
X-Trace-Id
Section-Io-Cache
X-FB-Debug
DC
X-B
X-TT
X-B3-Sampled
X-Contextid
X-Page-Id
X-Type
X-Fb-Rlafr
X-Oracle-Dms-Rid
X-N
X-Logged-In
X-Mobile
X-WP-CF-Super-Cache-Cache-Control
Viewport
X-WP-CF-Super-Cache
X-XRDS-LOCATION
X-Debug
X-Whom
X-Template
Charset
X-Language
Fastly-SIE
Fastly-SWR
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Time
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Cache-Grace
X-Content-Options
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Webkit-CSP
Version
X-Via-JSL
X-EdgeConnect-Cache-Status
X-Wix-Request-Id
X-RateLimit-Reset
X-Magnolia-Registration
Content-Disposition
X-App-Environment
X-Varnish-Grace
X-B-Cache
X-Signature
X-Node-Name
X-Origin-Cache
SRV
VIX-Pulpo-Node
X-ProcessESI
X-Amzn-Remapped-Content-Length
X-RemovedCookies
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel-1
X-Yottaa-Metrics
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Yottaa-Optimizations
X-Rule
X-Debug-IsConnected
SD-X-WS
X-Debug-IsPreview
X-UUID
Ms-Operation-Id
MS-CV
X-Amz-Replication-Status
X-Datadog-Sampled
X-Backend-Name
X-RTag
X-G
X-Hl-Ver
X-Adobe-Loc
X-FW-Version
X-Device-Type
ServerID
X-Adobe-Content
X-FW-Hash
X-Proxy-Cache-Info
X-FW-Server
X-FW-Serve
GEO-INFO
X-FW-Dynamic
X-FW-Type
X-Instance
X-Storage
X-FW-Static
X-Rendered-As
NGB
Liferay-Portal
X-User-Agent
X-Region
X-Is-Bot
X-IPS-LoggedIn
Country
X-Cacheable-TTL
X-Cache-Age
X-NYM-Debug-Backend
X-Status
X-Environment-Context
X-B3-SpanId
X-Cache-Hit
X-L-Path
X-Real-IP
X-NWS-UUID-VERIFY
X-Source
Countrycode
X-ServerID
X-Rid
Surrogate-Key
Akamai-GRN
X-Sucuri-Cache
X-Servername
X-Sucuri-ID
X-WP-CF-Super-Cache-Active
From-Origin
OT-Force-Account-Verify
Cross-Origin-Window-Policy
Amp-Access-Control-Allow-Source-Origin
X-VC-Cache
X-Xrds-Location
X-UA
X-WebKit-CSP-Report-Only
X-RM-Cache-TTL
Backend
Upgrade-Insecure-Requests
X-Framework
Front
X-INCAP-ABP
X-Mode
Refresh
X-Air-Pt
X-AB
Frame-Options
X-Cache-Time
X-Content-Powered-By
Xet-Cookie
X-B3-Traceid
X-DataDome
X-HTML-Minification-Powered-By
X-Akamai-Request-ID2
X-Buckets
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-RID
Url
X-Edge-Location
X-Handled-By
X-Endurance-Cache-Level
X-Nginx-Cache
X-VC
X-CDN-Forward
X-Wormhole-Sdk
Webserver
X-VWS-Id
X-JoinUs
X-LJ-Flow-ID
X-Xfnlog-Site
X-Webstats-RespID
Selected-Fe
Access-Control-Request-Headers
X-No-Session
X-Timing-Wait
X-Akamai-Edgescape
X-UPSTREAM-Address
X-Rn-Rsrv
X-Reqid
X-Azure-Ref-OriginShield
X-Proxy-Build
X-Vcache
X-Origin-CC
Filters
X-Rewrite-Enabled
X-Origin-TTL
X-Origin-Date
X-AWS-Id
X-SaId
X-RCS-CacheZone
Meta-Geo
X-Cluster
WPO-Cache-Status
Atl-Traceid
X-Git-Commit
WPO-Cache-Message
X-Logging-Id
X-Labrador-Cache-Channel
X-Tumblr-Pixel-2
X-IPLB-Request-ID
X-IPLB-Instance
X-VCT
X-Cache-Operation
Property-Id
X-Fetched-On
X-Drupal-Cache-Tags
X-Served-From
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Container-Uri
X-Origin-Hint
X-Provided-By
X-PHP-Host
Mn-Server-Ip
X-R9-Blue-Green-Version
X-Ms-Version
X-Origin
X-Ms-Request-Id
X-Cache-Rule
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Device-Class
TWC-Locale-Group
X-Generation-Time
TWC-Privacy
ServedBy
Thinkindot-CacheControl-Type
X-Cloudmap
X-Extlb
X-Accel-Version
X-Httpd
X-Cache-Debug
Cache
X-Cms-Context
X-Adobe-Source
TDXMobile
X-Drupal-Cache-Contexts
X-Hosted-By
Thinkindot-CacheControl
Section-Io-Id
X-CMSURLCustom
X-Cache-Status-Check
X-Scope-Id
Thinkindot-Control
X-Tb
X-Thinkindot-L3
X-BYPASS-REASON
X-Shield-Cache-Expires
X-Site-Version
X-Zipkin-Id
X-Web-Node
Web-Mar-Node
X-Locale
X-Varnish-Cache-Hits
X-Proxied
X-Restarts
X-Routing-Service
X-Redis-Cache
X-ProxyCache-Key
X-ProxyCache-Status
X-Cdn-Origin
X-Director
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-S
X-Format
X-Geo-Region
X-Tncms
X-Upstream-Ht
X-Browser-Name
X-Upstream-Ct
X-Is-Desktop
X-Is-Tablet
X-Is-Mobile
X-Varnish-Age
X-Lambda-Id
X-Skip-Cache
X-Is-Supported-Browser
X-Frame-Option
X-Soup
X-Loop
X-Tcp-Rtt
Apigw-Requestid
X-Forwarded-Host
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Cache-Hits
Xserver
X-Varnish-Beresp-Grace
X-Shopify-Stage
X-ShardId
X-ShopId
X-Cache-Host
X-Sorting-Hat-PodId
X-GeoCountry
X-GeoCode
X-Detected-As
Accept-Language
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-SRV
X-Worker
X-Generated-By
X-Lagoon
X-Vercel-Id
X-Vercel-Cache
X-Rocket-Nginx-Serving-Static
X-Optimistic-Header
Azure-SlotName
Azure-InstanceId
Azure-Version
Azure-SiteName
Azure-RegionName
Source
Node
X-Fastly-Request-Id
X-WP-CF-Super-Cache-Cookies-Bypass
CDN-RequestCountryCode
LB
CDN-PullZone
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
CDN-RequestPullCode
CDN-Uid
CDN-RequestPullSuccess
X-Request-URI
CDN-RequestId
Fastcgi-Useragent
X-App-Version
X-Pass-Why
Cross-Origin-Embedder-Policy
Protected
X-Vcl-Version
X-Tumblr-Pixel-3
X-Connection-Hash
Alternate-Protocol
X-XRDS-Location
Expiry
X-Tec-Api-Origin
X-GEO
X-Tec-Api-Root
X-Tec-Api-Version
X-Ratelimit-Reset
X-Cache-Server
X-ECache
X-TA-CDN-Provider
X-Jobs
DB-Nickname
X-Cache-Expired-At
Onion-Location
AMP-Access-Control-Allow-Source-Origin
X-Server-W
Sid
CF-IPCountry
X-PHP-Backend
X-Response-Served-From
X-Original-Request-Id
X-Api-Version
Environment
Uber-Trace-Id
X-Fastcgi-Cache
Priority
X-LSADC-Cache
X-Proxy-Cache-Status
X-Uri
X-MP-GENERATED-AT
X-Cache-Action
User-Cache-Control
X-Cluster-Node
X-TT-LOGID
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-LiteSpeed-Cache-Control
HostName
X-Tx-Id
X-Mg-Request-UUID
X-FB-TRIP-ID
WP-Super-Cache
X-Clientip
X-Mvc-Supplant-Cachable
X-Conf
X-Level-Front-Cache
X-Content-Age
X-Epic-Correlation-Id
X-Ec-Fail
X-Ec-GeoHdr
Gannett-Cam-Experience-Id
X-Op-Id-All
X-Org
X-Origin-Expires
X-Gen-Mode
Req-ID
X-Node-Id
X-Jungle-Id
X-ND-Cache
Rendered-Blocks
X-NMSegId
X-NCache
X-UA-Device-Type
MD5-Digest
A
Meta-Geo-Continent
X-Developer
X-Vtex-Remote-Cache
X-Dispatcher-Server
Magicmarker
X-GeoIP
X-GeoIP-City
Lang
X-Device-Os
X-Gzip
X-Generated-On
Origin
Origin-Agent-Cluster
Candidate-Md5Url
X-Cache-NE
X-Hnp-Log
Cache-Tv-Group
X-D
Ngx.Var.Host
NM-Fastcgi-Cache
X-Viewer-Country
X-Ig-Origin-Region
Fusion-Template-Id
DCR-Decision-By
X-TIM-N
Wxu-Next-Commit
Wxu-Next-Hostname
X-SB
Edge-Cache
Vix-Hermes-Req-Id
X-Esi-Check
Fusion-Component-Id
X-Rojux
Wxu-Next-Region
X-ScT
X-A-Wwc
DCR-Processing-Time-Ms
X-SRCache-Key
X-Test
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
X-Thanos
X-Bc-Bl
X-BCube-Filmed-By
X-Vdms-Path
X-Cache-Id
X-DC
Fusion-Content-Source
X-FC-Vary-Parameters
Fusion-Deployment-Id
X-Vdms-Version
Fusion-Source
X-Forwarded-Site
X-Platform
X-Aed
X-Varnish-Hostname
X-Block-Status
X-Bl-Debug
X-Bip
Fusion-Content-Id
T-Server
Sslversion
Content-Secure-Policy
X-Proto
Surrogated-Key
X-URL
X-Origin-Response-Time
Ha-Gx-Prefs
Fastly-SSL
L5d-Success-Class
HA-Ipaddr
Host-ID
X-Edge-Server
Fastly-Backend-Name
X-CGP
X-Cache-Bucket
W
Ssr
Sever-Int
Server-Host
Server-Hostname
We-Hiring
X-Backend-Instance
X-ApacheServer
X-AK-Request-ID
X-App-Name
X-Auth-Group-Type
X-Auto-Login
Server-Ext
X-Cache-Info
X-Csrf-Jwt
Origin-CC
X-CUA
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Origin-EX
PFcat
X-Cdn-Srv
X-Cache-TTL-Remaining
Release
Powered-By
X-Core-Value
Mail-Subject
CDCHOST
X-PERF
X-PAYTM-SRV-ID
X-Origin-Time
X-Pubstack
X-Varnishpool
X-Powered-By-VTEX-Cache
X-VarnishDD-TTL
X-Zone
X-Nyt-Route
X-Amz-Storage-Class
X-HS-Content-Campaign-Id
X-VG-WebCache
X-Loc
X-Nginx-Cache-Key
Esi-Enabled
X-Policy
X-RateLimit-Limit-Second
X-SD-PageType
X-Var-Ttl
X-Scheme
XM
Yak-Timeinfo
Cdn-Requestid
X-V-Cache
X-Newrelic-Synthetics
X-Varnish-Director
X-Region-Sid
X-RateLimit-Remaining-Second
X-Render-Time
X-Req
X-Request-Time
X-Request-Start
X-Via-Fastly
X-Mvc-Supplant-OutputCached
X-Geo-Header
X-Fmm-Version
C-Via
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Content-Script-Type
AKAMAI
X-From
X-HN
Canary
Cdn-Host
Cdn-Request-Time
Cache-Provider
Cdncip
X-Gdpr
Cdnsip
Content-Style-Type
X-Fastly-Cache
X-Service
X-Tt-Logid
X-VTEX-Cache-Time
X-WA-Info
X-VTEX-Cache-Server
X-Eu-Site
DSUID
X-SVT-ORM-VERSION
X-Tb-Optimization-Total-Bytes-Saved
X-SVT-ORM-RULES
X-Fastly-Backend
X-Server-IP
X-Section
X-Varnish-Authentication
Gh-Request-Id
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Sn-Servicetimems
X-Proxied-Request
X-Contensis-Viewer-Groups
X-Micro-Cache
X-Mly-Id
X-VG-TLSProxy
X-Men
X-Location
X-Ig-Push-State
X-Human
X-Hash
X-We-Are-Hiring
X-CacheTTL
X-DPWN-IS-SECURE
X-Ec-Custom-Error
X-Cache-Backend
X-Cache-Aspx
X-Pool
X-Varnish-Beresp-Status
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-GoCache-CacheStatus
X-Request-Host
Tube-Return
X-Dc
L
Machine
True-Client-Country-4JS
Is-Eu
Producers
Tube-Get-Contents
RNT-Time
RNT-Machine
Click-Count-Action-Start
Redirect-Candidate
Pramga
Platform
Req-Svc-Chain
X-Varnish-Beresp-Ttl
On-Server
Tube-Got-Eval
Fastly-GeoIP-CountryCode
Apple-News-Services-Request-Url
X-Acquia-Purge-Cdn-Unconfigured
Tube-Got-Results
X-Ad-Load-Variation
Click-Count-Error
Cache-Key
X-Aicache-OS
Apple-News-Services-Parsed-Url
X-Access
Web-Mar-Region
V-Age
Cluster
Apple-News-Services-Host
Adler-Geo
Apple-News-Services-Handled
Country-Code
X-AIR-PT
NGX
X-Date
X-Slack-Backend
Odigeo-Trace-Id
Proxy-Firewall
X-NGINX-Cache
X-Slack-Shared-Secret-Outcome
X-Accel-Expires-Debug
Datacenter
X-COUNTRY
Debug
X-Varnish-Hits
X-NodeID
X-Up
X-Custom-Header
X-Ismobilevalue
X-Cs
X-CACHE-GROUP
Locid
X-LB-ID
X-Nananana
X-Refresh
X-ID
X-Akamai-Transformed
X-Pad
X-Nf-Request-Id
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-DefHash
X-LiteSpeed-Tag
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-DefElseHash
X-Client-Ip
X-Amz-Meta-Cb-Modifiedtime
Pics-Label
CloudFront-Viewer-Country
Fastly-Drupal-HTML
Mime-Version
SID
X-VHOST
X-Depends
X-M-Log
X-Via-Popv
X-Via-Poph
X-M-Reqid
X-Servedbyhost
X-Via-Popn
X-HA-Backend
X-VC-TTL
X-Old-Content-Length
X-Cached-By
GeoIP-Latitude
X-Datadome
Ngx-Var-Key
X-Parent-Response-Time
X-LB-NoCache
X-CS
Fastly-Drupal-Html
X-Moov-Xdn-Version
X-Moov-T
X-CDN-Cache-Status
X-TH-Server
X-CACHE-AGE
X-Cache-FS-Status
X-B3-Parentspanid
X-TIME
Cross-Origin-Embedder-Policy-Report-Only
Resin-Trace
GeoIp-Country-Code
X-DynaTrace-JS-Agent
Cf-Ipcountry
Server-ID
NtCoent-Length
X-Nc
Server-Info
X-Wa
Cdn
X-Presslabs-Stats
X-User
Uri
X-B-Cookie
X-Vgn-Hpd-Reason
X-VCache
X-Application
X-Destination
Cf-Device-Type
BehaviorPad-Version
X-External-Request-Id
X-S-Cookie
X-Litespeed-Tag
X-NewRelic-App-Data
X-APP
FSS-Cache
True-Client-IP
X-ZONE
X-Srv
X-IAuth-Set-Uid
X-Zen-Fury
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Flags
X-Route-Name
X-Is-Crawler
X-Varnish-Beresp-TTL
CDN
X-Cache-Date
X-Sigma
X-Esi
X-Instance-Name
X-Fpc
X-Rocket-Build-Number
X-Sigma-Backend
X-TX-ID
X-HostName
X-API-Version
X-Dynatrace-Js-Agent
X-VServer
True-Client-Ip
X-DynaTrace
X-Content-Length
X-Vc
X-Branch-Name
X-Segment-20210421
X-HITS
Load-Balancing
Tcn
X-Oracle-DMS-ECID
X-Page-View
S-Rt
X-HOST
X-B3-Spanid
X-FPC
GeoIP-Country-Code
Serverhost
Hostname
Srv
Request-ID
Ohc-File-Size
X-WA
X-Cdn-Cache-Status
X-Dispatch
X-NC
X-Dispatcher-Number
X-DataCenter
X-Cdn-Forward
Product
Type
Vc-Max-Age
X-RequestId
Server-Id
X-APP-VERSION
X-Http-Reason
X-Sql-Duration-Ms
X-Sql-Count
X-Irp-Debug
X-FL-QIT-DEBUG
X-Webkit-Csp-Report-Only
Geoip-Latitude
Srvid
ServerName
X-Lb-Nocache
Cl-Cache
X-Geo
X-Bug-Bounty
WZWS-RAY
X-Owner
X-Via-Edge
IsBot
X-Ckpd-Fst-Backend
Edge-Copy-Time
X-SIPLIST1
X-Via-CDN
X-Via-SSL
X-ServedByHost
DataCenter
X-CSRF-TOKEN
X-VCL-Version
X-Via-PopV
X-Via-PopN
X-Core-Mission
Epwk-X-Cache
Cloudfront-Viewer-Country
Cross-Origin-Opener-Policy-Report-Only
X-Via-PopH
MIME-Version
XkeyRZ
X-Ha-Backend
X-Proxy-CacheRZ
X-Cst
Origin-Trial
CacheControlHeader
Ohc-Cache-HIT
X-Hit
X-Cache-Ttl
N-Cache
X-Qloud-Router
PICS-Label
CountryCode
X-Correlation-ID
X-Lb-Id
X-Ua
ServerHost
X-App
X-Srcache-Store-Status
Rtss
X-Srcache-Fetch-Status
X-MiniProfiler-Ids
X-Amz-Meta-Opti
X-Fastly-Country-Code
X-MSEdge-Features
X-MSEdge-Flight
Lb
X-Web-Server
X-Sqd-Ctime
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Acquia-Site
X-Sqd-Stime
X-Datacenter
Sm-Log-Id
X-Service-Response-Time
X-Acquia-Application-UUID
Warning
X-LAGOON
X-Udemy-Cache-App-Namespace
X-Amz-Meta-Sha256
X-Amz-Meta-S3b-Last-Modified
X-IN-APIGATEWAYSSL
X-Limited
X-UP
X-Vmg-Version
X-Akamai-Device-Characteristics
User-Agent
X-IN-APIGATEWAY
Akamai-Cache-Status
Cneonction
X-Dw-Trace-Id
X-Cdn-Request-ID
X-Check-Cacheable
X-Tenant
X-Serial
X-Th-Server
X-Proxy-Cache-La3
X-RAMCache
Xkeylog
Xkey-La3
X-Akamai-Pragma-Client-IP
X-Ramcache
X-Snapshot-Date
X-CF-Lambda-Fn
X-Requestid
X-Cache-Type
X-CF-Lambda-Version
X-Forwarded-Path
X-Shop-Environment
Ngx
X-Orig-Expires
Expect-Staple