Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Expect-CT
Accept-Ranges
Pragma
X-Powered-By
X-XSS-Protection
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
Alt-Svc
P3P
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
X-Served-By
CF-Ray
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Access-Control-Allow-Credentials
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
X-Drupal-Cache
X-Generator
X-Cache-Status
X-Check
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-Dns-Prefetch-Control
Timing-Allow-Origin
X-FRAME-OPTIONS
X-DNS-Prefetch-Control
X-Iinfo
X-Drupal-Dynamic-Cache
Feature-Policy
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
Server-Timing
X-XSS-PROTECTION
Access-Control-Max-Age
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Robots-Tag
X-Backend
X-Cache-Group
Cf-Edge-Cache
Keep-Alive
Host-Header
X-UA-Device
X-Proxy-Cache
X-Hacker
X-Server
X-Rq
X-Server-Powered-By
X-Age
Allow
X-Vhost
X-Varnish-Cache
X-Ws-Request-Id
X-Dispatcher
EagleId
X-Amz-Version-Id
Grace
X-LiteSpeed-Cache
P3p
Cf-Apo-Via
Nel
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Device
Cf-Railgun
EagleEye-TraceId
X-Aws-Lambda-Call-Status
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Pingback
X-Host
X-Node
Accept-CH
X-OneAgent-JS-Injection
X-Server-Id
X-Backend-Server
Surrogate-Control
X-CST
X-Nginx-Cache-Status
X-Readtime
X-Cache-Lookup
X-Akam-SW-Version
Permissions-Policy
X-Content-Security-Policy-Report-Only
Request-Id
X-Application-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Trace
Accept-Ch-Lifetime
X-Response-Time
X-Edge
X-HW
X-Ua-Compatible
Content-Location
X-Mod-Pagespeed
X-Clacks-Overhead
Accept-CH-Lifetime
X-Ruxit-JS-Agent
X-Midtier
X-ECACHE
X-Url
Rating
X-Amz-Server-Side-Encryption
X-Mcache
Xkey
X-ESI
X-Country
X-Litespeed-Cache
X-Oneagent-Js-Injection
X-Upstream
X-Vcap-Request-Id
Accept-Ch
X-Vname
X-TtlSet
X-PC
Cache-Tag
X-D2id
X-MS-InvokeApp
X-Rack-Cache
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Element-Page-Cache
Verso
X-Cdn-Fetch
X-Use-Magma
X-Exp-Id
X-Exp-Variant
X-Kinja
Edge-Control
RTSS
X-Cache-TTL
Fastly-Restarts
X-Powered-By-Plesk
X-VARITI-CCR
Origin-Trial
X-Ac
X-Navigation-Version
X-Ruxit-Js-Agent
X-Abt-Application-Version
X-Goog-Hash
X-Cached
X-Content-Type
Service-Worker-Allowed
X-Country-Code
X-WebKit-CSP-Report-Only
X-GitHub-Request-Id
X-Ttl
X-Sol
Display
Pagespeed
X-Middleton-Display
X-Amz-Rid
X-Browser-Type
X-Varnish-TTL
X-Mg-S
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Server-Name
Cross-Origin-Opener-Policy
X-B3-TraceId
Arr-Disable-Session-Affinity
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Powered-CMS
X-Amzn-Trace-Id
X-Middleton-Response
Response
AR-ATIME
AR-SID
AR-Request-ID
AR-PoweredBy
SPIisLatency
SPRequestDuration
X-Cache-Key
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Version
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Cnection
X-Times
X-Accel-Expires
X-T
Cache-Tags
X-NF-Request-ID
Cache-Status
Front-End-Https
X-Fastcgi-Cache
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Edge-Cache-Tag
X-MSEdge-Ref
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Px
X-Hits
Nginx-Cache
X-Ser
X-Client-IP
X-NWS-LOG-UUID
Public-Key-Pins
X-Kinja-CCPA
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Recruiting
X-B3-Traceid
X-LLID
X-Request-Processing-Time
X-Request-Received
X-Frontend
Server-Node
X-RateLimit-Remaining
Payment
X-Ua-Browser
X-Shield-Request-Id
X-Webkit-CSP
X-DIS-Request-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web
Access-Control-Request-Method
TP-Cache
X-Goog-Metageneration
X-RateLimit-Limit
S
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
MicrosoftSharePointTeamServices
TP-L2-Cache
X-LB-Cache
X-FastCGI-Cache
X-Content-Digest
Content-MD5
X-Distributor
X-Microsite
Realpath
X-Request-Handler-Origin-Region
X-Ezoic-Cdn
Access-Control-Allow-Method
X-Page-Id
X-Hostname
X-Forwarded-For
X-FB-Debug
X-Geo-Country
Accept-Charset
Fastcgi-Cache
X-Ratelimit-Remaining
X-GUploader-UploadID
X-Amz-Apigw-Id
X-Protected-By
X-Cluster-Name
X-Amzn-RequestId
X-Webkit-CSP-Report-Only
X-Rid
X-Correlation-Id
X-PressLabs-Stats
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Seen-By
X-TEC-API-ORIGIN
X-Envoy-Decorator-Operation
X-B3-Sampled
X-XRDS-Location
Cleartype
TCN
X-Goog-Stored-Content-Length
DC
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Referer-Policy
X-Ratelimit-Limit
X-Newrelic-App-Data
X-Mobile
X-Origin-Cache
X-Origin-Server
X-Debug-Info
X-Webkit-Csp
Cross-Origin-Resource-Policy
X-Aspnet-Version
X-TTL
X-Varnish-Backend
X-Ua-Device
X-Git-Hash
X-Logged-In
X-Contextid
X-Varnish-Grace
X-Azure-Ref
X-Server-ID
X-Route-Name
X-Revision
X-Fb-Rlafr
X-Flags
X-Aspnet-Duration-Ms
X-App-Environment
Surrogate-Key
X-Amz-Replication-Status
X-Grace
X-Content-Options
X-Request-Guid
X-Is-Crawler
X-Providence-Cookie
X-Edge-Location-Klb
Count-Hit
X-IPS-LoggedIn
X-Kinsta-Cache
X-TT
Alternate-Protocol
X-Amz-Meta-S3cmd-Attrs
X-Client-Ip
Healthy
X-Wix-Request-Id
X-Forwarded-Proto
X-App-Server
X-Hosted-By
Frame-Options
X-Whom
Charset
WPO-Cache-Message
WPO-Cache-Status
MS-Author-Via
X-Akamai-Edgescape
Viewport
X-Daa-Tunnel
X-Magnolia-Registration
Retry-After
Filterid
X-Oracle-Dms-Ecid
Paypal-Debug-Id
X-Oracle-Dms-Rid
X-B
X-Backend-Name
X-F-Cache
SRV
Section-Io-Cache
X-Id
Amp-Access-Control-Allow-Source-Origin
X-RateLimit-Reset
X-AppVersion
X-Az
X-Activity-Id
X-Proxy-Cache-Info
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Trace-Id
X-Cache-Control
Server-Name
X-Www-Served-By
X-Cache-Age
X-App-Version
X-Type
X-ARC
X-Rule
X-Instance
X-Response-Served-From
X-Http-Reason
X-Varnish-Server
SD-X-WS
Host
VIX-Pulpo-Node
X-Cache-Rule
Akamai-GRN
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
Front
Protected
X-Proxy
X-Akamai-Request-ID2
X-Rocket-Nginx-Serving-Static
X-Status
X-Cache-Grace
X-UUID
X-Edge-Location
Refresh
X-EdgeConnect-Cache-Status
X-Varnish-Age
X-User-Agent
X-Cacheable-TTL
X-Page-View
X-FW-Serve
X-FW-Server
X-Rendered-As
X-FW-Static
X-FW-Version
X-Jobs
Fastly-SIE
X-Is-Bot
X-L-Path
Fastly-SWR
X-FW-Hash
From-Origin
X-FW-Type
X-Region
X-Unique-Id
X-FW-Dynamic
X-COUNTRY
X-Environment-Context
X-Framework
Access-Control-Request-Headers
X-Adobe-Loc
X-N
X-Cache-Time
X-Adobe-Content
X-Tumblr-Pixel-0
X-G
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-RemovedCookies
Version
X-Tumblr-User
X-ProcessESI
X-Load-Cache
X-Time
ServerID
X-Language
Country
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Source
X-Datadog-Trace-Id
X-Vcache
X-CDN-Forward
Content-Disposition
X-Drupal-Cache-Tags
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Upgrade-Enabled
X-DataDome
X-Mg-Request-UUID
X-Datadog-Sampled
X-HTML-Minification-Powered-By
X-Amzn-Remapped-Content-Length
Accept-Language
X-Debug-IsConnected
X-Debug-IsPreview
Countrycode
X-DynaTrace
X-Nf-Request-Id
X-ID
X-Tt-Trace-Host
X-Tt-Trace-Tag
Xet-Cookie
X-Generated-By
X-Signature
X-B-Cache
Backend
CF-IPCountry
X-ECache
X-Varnish-Ttl
X-DynaTrace-JS-Agent
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Nginx-Cache
X-B3-SpanId
Xserver
Liferay-Portal
X-Httpd
X-Mode
X-Servername
X-Erf-Web-Scheduler
Webserver
X-NYM-Debug-Backend
X-Tt-Logid
Url
X-Device-Type
X-Content-Age
X-Content-Powered-By
X-Drupal-Cache-Contexts
X-Zen-Fury
X-Xrds-Location
X-Tb
Fastcgi-Useragent
X-Urbn-Site-Id
X-Varnish-Cache-Hits
X-Say-TTL
X-Urbn-Context-Path
X-Proto
X-SaId
X-Cache-Operation
X-Rewrite-Enabled
X-LAGOON
S-Rt
X-Git-Commit
X-GeoCountry
X-GeoCode
X-Director
X-JoinUs
X-Cache-Action
X-Container-Uri
X-Sucuri-ID
X-UPSTREAM-Address
Filters
GEO-INFO
X-Sucuri-Cache
Azure-Version
Azure-SlotName
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Locale
Load-Balancing
X-ServerID
Onion-Location
X-SayCDN-TTL
Meta-Geo
X-Say-Cacheable
X-Soup
X-RM-Cache-TTL
X-Cluster-Node
X-VC-Cache
X-Labrador-Cache-Channel
X-PHP-Host
X-Varnish-Hostname
X-Forwarded-Host
Uber-Trace-Id
X-Storage
X-Cache-Server
X-Ms-Version
X-Served-From
X-Adobe-Source
Web-Mar-Node
X-Sql-Count
X-Ms-Request-Id
CDN-RequestId
X-Logging-Id
X-VCT
X-Generation-Time
X-Detected-As
X-Sql-Duration-Ms
X-Routing-Service
TWC-Device-Class
TWC-Connection-Speed
DB-Nickname
TWC-GeoIP-Country
X-Skip-Cache
Mn-Server-Ip
Node
Webcakes-App-Version
X-Origin-Hint
X-Proxied
X-Debug
X-Extlb
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-RCS-CacheZone
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
Webcakes-Region
TWC-GeoIP-LatLong
Property-Id
X-Zipkin-Id
X-Proxy-Build
X-Timing-Wait
X-Fetched-On
X-Tumblr-Pixel-2
X-Lambda-Id
X-Tumblr-Pixel-3
X-Format
Selected-Fe
X-Uri
X-LSADC-Cache
X-Template
OT-Force-Account-Verify
X-URL
Source
Fastly-Drupal-HTML
X-MP-GENERATED-AT
X-Origin-Date
X-XRDS-LOCATION
X-MCACHE
X-Tncms
X-Loop
X-Cache-Hit
X-Cache-Expired-At
X-Tec-Api-Version
X-Pass-Why
X-Tec-Api-Origin
X-Tec-Api-Root
X-Varnish-Hits
X-Endurance-Cache-Level
X-Ratelimit-Reset
X-Redis-Cache
X-Srv
Content-Secure-Policy
X-Ua
X-Cache-TTL-Remaining
Cross-Origin-Window-Policy
Upgrade-Insecure-Requests
X-UA-Device-Type
X-Via-JSL
X-Fastly-Request-Id
X-Real-IP
X-Origin-TTL
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-CCDN-Origin-Time
X-Origin-CC
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Pubstack
X-Node-Name
X-AIR-PT
X-NGENIX-Cache
X-Rn-Rsrv
X-Server-W
X-TimeS
X-S
X-GEO
X-CACHE-AGE
Cache-Provider
Cache-Hits
NGB
CDN-Cache
CDN-CachedAt
X-RTag
CDN-RequestCountryCode
CDN-RequestPullSuccess
MS-CV
CDN-Uid
X-Cache-Host
Ms-Operation-Id
CDN-RequestPullCode
CDN-EdgeStorageId
CDN-PullZone
X-Datadome
Cache-Name
X-Aspnetmvc-Version
X-Hl-Ver
X-PHP-Backend
X-Akamai-Transformed
X-Presslabs-Stats
X-Restarts
X-Reqid
X-Newrelic-Synthetics
X-Xfnlog-Site
X-IPLB-Instance
X-IPLB-Request-ID
X-Cache-Type
X-Cms-Context
X-Optimistic-Header
Apigw-Requestid
X-CSRF-Token
X-No-Session
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Parent-Response-Time
X-A-Wwc
Fastly-SSL
Gh-Request-Id
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
X-A-Dcw
X-A-Dgt
Gannett-Cam-Experience-Id
DCR-Decision-By
CPC-Cache
HA-Ipaddr
CPC-Age
Candidate-Md5Url
Canary
DCR-Processing-Time-Ms
X-Application
X-Accel-Expires-Debug
X-Aed
Fastly-Backend-Name
X-App
X-Accel-Buffering
Odigeo-Trace-Id
Sslversion
Surrogated-Key
Server-Host
Rendered-Blocks
Web-Mar-Region
T-Server
True-Client-Country-4JS
W
VNS-Age
We-Hiring
Vix-Hermes-Req-Id
X-A
Redirect-Candidate
Magicmarker
X-A-Dam
Lang
L5d-Success-Class
Mail-Subject
MD5-Digest
Ngx.Var.Host
N-Cache
X-A-Ccd
Meta-Geo-Continent
L
X-Dispatcher-Number
X-Request-Host
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Rojux
X-S-Cookie
X-SD-PageType
X-ScT
X-Policy
X-Origin-Time
X-Is-Gdpr
X-Irp-Debug
X-JWT-State
X-Mvc-Supplant-Cachable
X-Orig-Expires
X-Nyt-Route
X-Shop-Environment
X-Slack-Backend
X-Wikidot-Backend
X-We-Are-Hiring
X-Vtex-Remote-Cache
X-Wikidot-Static-Cache
X-Wix-Viewer-Type
Xc-Version
X-Worker
X-Viewer-Country
X-VG-WebCache
X-SRCache-Key
X-Slack-Shared-Secret-Outcome
X-Tenant
X-Var-Ttl
X-Vdms-Version
X-Vdms-Path
X-Has-Esi
X-GeoIP-Region-Code
X-CGP
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Conf
X-Csrf-Jwt
X-Date
X-D
X-Cdn-Diag
X-CacheTTL
X-BCube-Filmed-By
X-Bc-Bl
X-Bl-Debug
X-Cache-Bucket
X-Cache-NE
X-Cache-Info
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Fastly-Backend
X-External-Request-Id
X-FC-Vary-Parameters
X-Forwarded-Path
X-GeoIP-Country-Code
X-Gdpr
X-Eu-Site
X-Epic-Correlation-Id
X-Developer
X-Destination
BehaviorPad-Version
X-Ec-Custom-Error
X-Ec-GeoHdr
X-Ec-Fail
X-B-Cookie
VNS-Cache
X-Handled-By
X-LJ-Flow-ID
X-Via-Fastly
X-TIME
X-Cluster
X-AWS-Id
X-VWS-Id
TDXMobile
X-Loc
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Level-Front-Cache
X-Human
X-INCAP-ABP
X-Mid
Thinkindot-Control
X-Access
Origin
Platform
X-Org
X-Origin-Response-Time
X-PAYTM-SRV-ID
X-Owner
Producers
X-Old-Content-Length
X-Nitro-Cache
X-Hash
X-Cdn-Origin
Req-Svc-Chain
Release
X-Mly-Id
X-Geo-Header
X-BBC-Edge-Cache-Status
X-Core-Mission
X-Core-Value
X-Section
X-TA-CDN-Provider
X-Bip
X-CMSURLCustom
X-Clara-WADP
X-Cache-Id
X-Clientip
X-Cache-Debug
X-Auto-Login
X-DefElseHash
X-Fmm-Version
X-Forwarded-Site
X-Generated-On
X-PERF
X-Esi-Check
X-DPWN-IS-SECURE
X-DefHash
X-App-Name
X-ApacheServer
X-Alternate-Cache-Key
X-Gzip
X-Node-Id
X-Test
X-SVT-ORM-VERSION
X-Thanos
Expect-Staple
X-Up
Environment
X-SVT-ORM-RULES
ServedBy
Is-Eu
X-Sorting-Hat-PodId
Host-ID
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Variation
X-Varnish-CookieHashed-On
Adler-Geo
X-Vmg-Version
AKAMAI
X-VServer
X-WADP-Cache
X-VG-TLSProxy
X-Varnishpool
X-Varnish-CookieINHashed-On
Datacenter
X-Varnish-Remaining-TTL
Cmstype
Cmsid
X-Sn-Servicetimems
X-Thinkindot-L3
X-ShardId
X-Platform
X-Pool
X-Qloud-Router
Machine
Memcached
X-S-Maxage
X-Shopify-Stage
X-Server-IP
X-ShopId
X-Request-Time
X-Proxy-Cache-Status
X-Tx-Id
User-Cache-Control
X-Scale
X-Akamai-Device-Characteristics
X-Dispatcher-Server
CloudFront-Viewer-Country
Apple-News-Services-Handled
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Cdn-Srv
X-Block-Status
X-WA-Info
X-Device-Os
X-NodeID
CDCHOST
X-Origin
Country-Code
DSUID
Apple-News-Services-Host
X-GeoIP
Esi-Enabled
NM-Fastcgi-Cache
Server-Ext
X-Hnp-Log
X-From
X-Nananana
X-Gen-Mode
X-Mvc-Supplant-OutputCached
X-TIM-N
Sever-Int
X-Nginx-Cache-Key
Server-Hostname
X-NCache
X-LB-NoCache
C-Via
Server-Info
X-Cache-Enabled
X-Vcl-Version
Origin-CC
Wxu-Next-Commit
WP-Super-Cache
Wxu-Next-Hostname
Wxu-Next-Region
Ssr
Pics-Label
X-Op-Id-All
X-Instance-Name
X-Refresh
Origin-EX
X-Air-Trace-Id
Hostname
X-Air-Source
X-Air-Hostname
Time
Server-ID
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Status-Check
Memory
X-Cs
X-API-Version
X-Web-Node
X-HA-Backend
Origin-Agent-Cluster
X-Azure-Ref-OriginShield
Cf-Device-Type
X-ZONE
GeoIP-Latitude
NGX
X-VHOST
X-Tb-Optimization-Total-Bytes-Saved
AMP-Access-Control-Allow-Source-Origin
X-CACHE-GROUP
X-Correlation-ID
Cache-Host
X-Origin-Expires
X-Platform-Cluster
X-Microcachable
X-Platform-Processor
X-Platform-Router
X-DC
XM
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Dc
X-Wp-Cf-Super-Cache-Active
X-Internal-Host
X-VarnishDD-TTL
X-Fpc
X-Micro-Cache
X-Site-Version
X-Vgn-Hpd-Reason
X-HN
X-Locale
PFcat
Resin-Trace
YJS-ID
X-Ad-Defer-Variation
X-Webkit-Csp-Report-Only
Srvid
Locid
A
X-Via-Edge
Edge-Copy-Time
X-Via-CDN
X-Via-SSL
X-FL-EDGE
X-FL-QIT-DEBUG
X-TraceId
X-WP-CF-Super-Cache-Active
X-Zone
X-AB
Cdn-Requestid
X-DataCenter
X-Github-Request-Id
X-Pod-Name
X-LiteSpeed-Cache-Control
X-B3-Spanid
X-Buckets
Location
X-Moov-T
X-Cache-ASPX
X-Moov-Xdn-Version
X-Cached-By
X-Contensis-Viewer-Groups
X-FireWall-Port
User-Agent
X-Geo-Region
Sid
X-B3-Parentspanid
Uri
X-ATG-Version
X-Upstream-Ht
X-Upstream-Ct
X-Info
IsBot
X-Backend-Instance
X-Varnish-Authentication
X-FTR-Request-ID
Cache-Key
X-SIPLIST1
True-Client-Ip
X-Accel-Version
GeoIP-Country-Code
CF-Ctrl
X-NGINX-Cache
GeoIp-Country-Code
X-Esi
X-Nitro-Cache-From
X-Nitro-Rev
X-Is-Mobile
SID
X-Is-Supported-Browser
X-Is-Tablet
X-Tcp-Rtt
X-Is-Desktop
X-Browser-Name
X-Platform-Server
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Cdn
X-MSEdge-Features
X-HS-Content-Campaign-Id
State
X-CS
X-CSRF-TOKEN
X-MSEdge-Flight
X-VCache
X-LiteSpeed-Tag
True-Client-IP
X-Release
XServer
NtCoent-Length
X-Datacenter
X-Fastly-Cache
X-Provided-By
X-VC
X-NewRelic-App-Data
X-Cache-Remote
X-Sigma
Lb
Epwk-X-Cache
X-Hyper-Cache
X-Rocket-Build-Number
X-Sigma-Backend
Path
X-RN-RSRV
X-Geo
Cache
X-HS-Status
X-TRACE-ID
X-Vgn-Hpd-Variations-Key
X-SRV
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Api-Version
Fastly-Drupal-Html
X-GeoIP-City
X-Gamma-Serve
X-Frame-Option
X-Generated-In
X-Scheme
X-Webstats-RespID
X-FPC
X-Service
X-HostName
Tcn
X-GoCache-CacheStatus
WebServer
Cf-Ipcountry
X-Pad
Serverid
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
CountryCode
X-APP-VERSION
X-UA
Ohc-File-Size
X-Air-Pt
X-Amz-Meta-Opti
X-AK-Request-ID
Cdnsip
Cdncip
Cache-Tv-Group
X-Guploader-Uploadid
Cdn-Request-Time
X-Edge-Server
X-Wp-Cf-Super-Cache-Cache-Control
X-Vercel-Id
X-Branch-Name
X-Vercel-Cache
X-Traceid
X-Wp-Cf-Super-Cache
Cdn-Host
X-Origin-Cache-Key
Kp-EeAlive
X-EC-Lua
X-Cache-Ttl
X-Wp-Cf-Super-Cache-Cookies-Bypass
LB
X-Country-Code-Real
X-Cdn-Cache-Status
Env
Req-ID
M-TraceId
X-Proxy-CacheRZ
X-Mobile-URL
WZWS-RAY
Yak-Timeinfo
X-Location
Proxy-Connection
X-FTR-Backend
X-Vc
XkeyRZ
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Expires
X-NMSegId
CDN
X-Cdn-Request-ID
X-CACHE-KEY
X-VCL-Version
HostName
CacheControlHeader
X-Edge-Pop
X-Men
Cluster
X-Akamai-Pragma-Client-IP
X-Ad-Load-Variation
Srv
X-Aicache-OS
X-Developers
X-NWS-UUID-VERIFY
On-Server
Ngx
Ohc-Cache-HIT
X-Region-Sid
Geoip-Latitude
X-Cdn-Forward
X-Cache-Tags
X-Lb-Cache
X-Scope-Id
X-Request-Start
Content-Style-Type
Content-Script-Type
X-Acquia-Purge-Cdn-Unconfigured
X-Ha-Backend
X-TX-ID
X-M-Log
X-M-Reqid
X-Cache-FS-Status
X-B3-Trace-ID
X-CDN-Cache-Status
Server-Id
Pramga
V-Age
X-SB
X-Req
X-Servedbyhost
Tube-Get-Contents
RNT-Time
X-LB-ID
CF-Cached-On
X-Nc
RNT-Machine
Mime-Version
X-Minions-Version
X-WP-CF-Super-Cache-Cookies-Bypass
X-V-Cache
X-Wa
X-Via-Popn
X-Via-Poph
Tube-Got-Eval
Click-Count-Action-Start
Tube-Return
Click-Count-Error
X-Via-Popv
Tube-Got-Results
X-TT-LOGID
X-Tim-N
X-MiniProfiler-Ids
X-Fastly-Country-Code
X-Varnish-Beresp-Status
X-Check-Cacheable
ENV
X-Qnm-Cache
X-Request-URI
X-Shield-Cache-Expires
X-Lb-Nocache
X-Edge-POP
X-Snapshot-Date
X-Dw-Trace-Id
X-Acquia-Site
X-Acquia-Purge-Tags
PICS-Label
X-Acquia-Application-Trace
X-IN-APIGATEWAY
WWW-Authenticate
X-IN-APIGATEWAYSSL
X-Via-Ucdn
X-Acquia-Application-UUID
Yjs-Id
Vha6-Origin
X-Cached-Since
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
Edge-Cache
X-RAMCache
X-ElasticPress-Query
X-Litespeed-Cache-Control
Log-Origin
X-Iauth-Set-Uid
X-User
X-Fastly-Backend-Reqs
X-Miniprofiler-Ids
CACHE-MISS-TO-ORIGIN
Cneonction