Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-AspNet-Version
P3p
X-Runtime
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Ua-Compatible
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
Cf-Edge-Cache
X-Backend
Request-Context
X-UA-Device
Keep-Alive
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Age
X-Proxy-Cache
X-Rq
Xkey
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Page-Speed
X-Pingback
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Aws-Lambda-Call-Status
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Litespeed-Cache
X-Cache-Lookup
X-Application-Context
X-Country-Code
X-Trace
Content-Location
X-Country
X-Ruxit-JS-Agent
Service-Worker-Allowed
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Origin-Cache-Key
Accept-Ch-Lifetime
X-Edge
X-Rack-Cache
Cross-Origin-Opener-Policy
X-Amz-Server-Side-Encryption
X-ECACHE
Cache-Tag
X-Mcache
X-Midtier
X-FTR-Request-ID
X-Mod-Pagespeed
Nginx-Cache
X-MS-InvokeApp
X-TtlSet
X-Vname
X-PC
X-Upstream
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-Server-Name
X-Browser-Type
X-D2id
X-Element-Page-Cache
X-Times
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-Exp-Variant
Verso
X-GoogleNews-Bot
X-Cnection
X-Ruxit-Js-Agent
SPIisLatency
SPRequestDuration
X-Ac
AR-ATIME
AR-SID
AR-Request-ID
AR-PoweredBy
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-Navigation-Version
X-Abt-Application-Version
X-Vcap-Request-Id
X-Ser
X-Dw-Request-Base-Id
X-NF-Request-ID
X-GitHub-Request-Id
X-RateLimit-Remaining
X-NWS-LOG-UUID
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
AR-CACHE
X-VARITI-CCR
X-Mg-S
S
Pagespeed
X-Middleton-Display
Display
X-Sol
Edge-Cache-Tag
X-Cache-Key
RTSS
X-Client-IP
X-Ttl
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Cache-TTL
X-Powered-CMS
Accept-Ch
X-Goog-Hash
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
Cache-Status
X-Edge-Location-Klb
X-Kinsta-Cache
X-Server-ID
X-Version
Access-Control-Request-Method
X-Recruiting
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-ARC
Origin-Trial
X-Varnish-TTL
X-Content-Digest
X-TraceId
Response
X-Middleton-Response
Arr-Disable-Session-Affinity
X-Forwarded-For
X-T
X-Content-Security-Policy-Report-Only
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
X-Accel-Expires
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Hits
X-Daa-Tunnel
X-Cached
Public-Key-Pins
Cross-Origin-Resource-Policy
X-Id
Front-End-Https
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
MS-Author-Via
X-FTR-Expires
X-DIS-Request-ID
X-Request-Processing-Time
X-HS-Content-Id
Server-Node
X-HS-Hub-Id
X-Request-Received
X-HS-Cache-Config
X-HS-Combine-CSS
X-Ua-Browser
Payment
X-Frontend
X-Forwarded-Proto
X-Webkit-Csp
X-ORACLE-DMS-RID
X-FastCGI-Cache
X-LLID
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
Realpath
X-Fastcgi-Cache
X-Protected-By
X-GUploader-UploadID
TP-L2-Cache
X-LB-Cache
Cache-Tags
X-Distributor
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Origin-Server
X-ORACLE-DMS-ECID
X-Request-Handler-Origin-Region
X-Microsite
X-RateLimit-Limit
X-Ratelimit-Limit
Count-Hit
X-Page-Id
X-XRDS-LOCATION
X-Geo-Country
X-Az
X-Activity-Id
X-AppVersion
Referer-Policy
MRF-Tech
X-Debug-Info
X-F-Cache
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Cluster-Name
X-Hostname
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Varnish-Backend
X-Www-Served-By
Host
X-NGENIX-Cache
X-App-Server
Accept-Charset
X-Envoy-Decorator-Operation
Fastcgi-Cache
X-Correlation-Id
X-Varnish-Server
X-Ua-Device
X-PressLabs-Stats
X-TTL
X-FB-Debug
X-Goog-Metageneration
Access-Control-Allow-Method
X-Git-Hash
X-RateLimit-Reset
X-CSRF-Token
Retry-After
X-WebKit-CSP-Report-Only
X-Upgrade-Enabled
X-Load-Cache
X-Ezoic-Cdn
X-TEC-API-VERSION
X-Varnish-Ttl
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Kinja-CCPA
X-Content-Options
X-Fastly-Request-Id
Server-Name
X-Datadog-Trace-Id
X-Revision
X-Contextid
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Px
X-Tt-Trace-Host
X-Seen-By
X-Request-Guid
X-Tt-Trace-Tag
X-Cache-Control
DC
X-Grace
Section-Io-Cache
Charset
X-Trace-Id
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
Cleartype
X-Type
TCN
X-TT
X-Signature
X-B3-Sampled
X-B-Cache
X-B
X-App-Environment
X-Fb-Rlafr
X-Whom
Healthy
X-Rid
X-Newrelic-App-Data
X-Node-Name
X-Wix-Request-Id
Frame-Options
X-Mobile
X-Origin-Cache
X-Amz-Replication-Status
X-Magnolia-Registration
X-Aspnet-Duration-Ms
X-Route-Name
X-EdgeConnect-Cache-Status
X-Flags
X-Providence-Cookie
X-Is-Crawler
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Azure-Ref
X-Oracle-Dms-Ecid
X-Fastly-Request-ID
X-Proxy
X-Logged-In
X-Language
Filterid
X-Ratelimit-Remaining
X-N
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Content-Disposition
X-Air-Pt
Backend
X-Oracle-Dms-Rid
Akamai-GRN
X-Original-Request-Id
NGB
VIX-Pulpo-Node
Upgrade-Insecure-Requests
VIX-Pulpo-Upstream-Status
X-Template
X-Response-Served-From
X-Proxy-Cache-Info
Refresh
SD-X-WS
X-Datadog-Sampled
X-Debug-IsConnected
X-Tumblr-User
X-Tumblr-Pixel
X-Debug-IsPreview
X-Tumblr-Pixel-0
X-RemovedCookies
X-Tumblr-Pixel-1
X-ProcessESI
X-App-Version
X-Unique-Id
X-Time
X-Is-Bot
X-Rendered-As
X-Yottaa-Optimizations
X-Cache-Age
X-Varnish-Grace
X-Yottaa-Metrics
X-Adobe-Content
X-Adobe-Loc
X-IPS-LoggedIn
Viewport
X-UUID
X-RTag
X-Amzn-Remapped-Content-Length
Liferay-Portal
X-Servername
MS-CV
Ms-Operation-Id
X-FW-Version
X-FW-Type
X-Cacheable-TTL
X-FW-Static
X-Cache-Grace
X-G
X-FW-Dynamic
X-Debug
X-FW-Hash
X-FW-Serve
X-Instance
X-FW-Server
X-Environment-Context
From-Origin
Fastly-SIE
Fastly-SWR
X-L-Path
X-User-Agent
X-Hl-Ver
X-Backend-Name
X-Cache-Hit
X-Region
X-Device-Type
X-Rule
Country
Url
X-NYM-Debug-Backend
X-Jobs
X-Status
ServerID
X-Webkit-CSP
X-B3-SpanId
X-Via-JSL
X-Page-View
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-VC-Cache
Countrycode
X-Origin-TTL
X-Origin-CC
X-INCAP-ABP
Alternate-Protocol
WPO-Cache-Message
WPO-Cache-Status
Surrogate-Key
X-Air-Hostname
X-Air-Trace-Id
X-Cache-Status-Check
X-Hosted-By
X-Air-Source
X-HTML-Minification-Powered-By
X-NODE
Version
X-Akamai-Request-ID2
X-Content-Powered-By
Protected
X-Source
X-B3-Traceid
X-Akamai-Edgescape
X-Rocket-Nginx-Serving-Static
GEO-INFO
X-Tec-Api-Root
X-WP-CF-Super-Cache-Active
X-Tec-Api-Version
X-Storage
X-Tec-Api-Origin
Amp-Access-Control-Allow-Source-Origin
X-Accel-Version
CDN-RequestId
X-Http-Reason
X-Nginx-Cache
Access-Control-Request-Headers
X-Framework
X-VC
SRV
OT-Force-Account-Verify
X-Cache-Rule
X-Edge-Location
Front
X-Real-IP
AMP-Access-Control-Allow-Source-Origin
X-Mode
X-Use-Mantle
Xet-Cookie
X-Cache-Operation
X-Xfnlog-Site
X-UPSTREAM-Address
X-Upstream-Ct
Filters
Meta-Geo
Webserver
X-Upstream-Ht
X-Rn-Rsrv
Accept-Language
X-ServerID
X-Httpd
X-CDN-Forward
X-Rewrite-Enabled
X-Director
X-Proxy-Build
Selected-Fe
X-Soup
X-Varnish-Cache-Hits
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Origin
X-SaId
CF-IPCountry
X-Served-From
X-JoinUs
X-Timing-Wait
X-Cache-Time
X-SayCDN-TTL
X-Web-Node
X-Worker
X-Labrador-Cache-Channel
X-PHP-Host
ServedBy
X-Logging-Id
X-Redis-Cache
X-Say-TTL
X-Adobe-Source
X-Handled-By
X-Cache-Debug
X-Endurance-Cache-Level
Node
X-Say-Cacheable
X-Detected-As
Azure-SiteName
X-Varnish-Beresp-Grace
X-RM-Cache-TTL
X-Tncms
DB-Nickname
Azure-Version
Azure-SlotName
Azure-RegionName
X-AB
X-VCT
Azure-InstanceId
X-Is-Desktop
X-GeoCountry
X-GeoCode
X-Geo-Region
X-Is-Mobile
X-Is-Supported-Browser
X-Browser-Name
X-Loop
X-Is-Tablet
X-Skip-Cache
X-Tcp-Rtt
X-Varnish-Age
X-Cms-Context
Webcakes-App-Version
Webcakes-App-Name
Section-Io-Id
TWC-Privacy
Webcakes-Region
X-BYPASS-REASON
X-No-Session
X-Lambda-Id
X-S
X-Origin-Hint
TWC-Locale-Group
Web-Mar-Node
X-ProxyCache-Key
TWC-GeoIP-LatLong
X-ProxyCache-Status
X-Server-W
Property-Id
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
X-Cache-Server
X-RCS-CacheZone
X-Fetched-On
X-Vercel-Cache
X-DynaTrace
X-Restarts
X-Tb
X-VWS-Id
X-Site-Version
X-AWS-Id
Cross-Origin-Embedder-Policy
Apigw-Requestid
X-Vercel-Id
X-Locale
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-IPLB-Request-ID
X-IPLB-Instance
X-Format
X-Generation-Time
X-Platform-Cluster
X-Provided-By
X-Uri
X-Platform-Processor
X-Zipkin-Id
X-Ms-Version
X-Ms-Request-Id
X-Proxied
X-Container-Uri
X-Git-Commit
X-Reqid
X-Cache-Host
X-Extlb
Mn-Server-Ip
X-Cluster
X-Routing-Service
X-Frame-Option
X-Platform-Router
X-Forwarded-Host
Xserver
X-TT-LOGID
X-Webstats-RespID
X-MP-GENERATED-AT
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-XRDS-Location
X-Sql-Count
Cache-Tv-Group
X-Origin-Date
X-Sql-Duration-Ms
WP-Super-Cache
Source
Priority
Fastcgi-Useragent
CDN-PullZone
CDN-RequestCountryCode
Content-Secure-Policy
X-Alternate-Cache-Key
CDN-RequestPullSuccess
CDN-EdgeStorageId
X-Shopify-Stage
X-Vcache
X-Storefront-Renderer-Rendered
CDN-Cache
CDN-CachedAt
CDN-Uid
CDN-RequestPullCode
X-FB-TRIP-ID
X-Vcl-Version
X-Sucuri-Cache
X-Sucuri-ID
X-Generated-By
X-Sorting-Hat-ShopId
Onion-Location
X-ShardId
X-Cdn-Origin
X-ShopId
X-Sorting-Hat-PodId
Sid
X-Content-Age
Cross-Origin-Embedder-Policy-Report-Only
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-SRV
X-Pass-Why
X-Newrelic-Synthetics
S-Rt
WZWS-RAY
X-Buckets
Atl-Traceid
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Use-Magma
X-CMSURLCustom
X-Scope-Id
X-Cluster-Node
TDXMobile
X-Thinkindot-L3
X-Shield-Cache-Expires
Thinkindot-CacheControl
X-LSADC-Cache
X-Cache-Action
X-Ua
Cache
HostName
X-Xrds-Location
X-Proxy-Cache-Status
Cross-Origin-Window-Policy
X-VCache
Edge-Copy-Time
X-Varnish-Beresp-Ttl
X-Via-Edge
X-Datadome
X-GEO
X-Via-CDN
X-Via-SSL
X-WP-CF-Super-Cache-Cookies-Bypass
X-Cache-Expired-At
X-DataDome
Origin
Origin-Agent-Cluster
Ngx-Var-Key
Ngx.Var.Host
MD5-Digest
Redirect-Candidate
Candidate-Md5Url
DCR-Decision-By
DCR-Processing-Time-Ms
Lang
Gannett-Cam-Experience-Id
Meta-Geo-Continent
X-A-Dgt
X-Optimistic-Header
X-PAYTM-SRV-ID
X-Platform
X-Request-Start
X-External-Request-Id
X-Epic-Correlation-Id
X-Developer
X-Dispatcher-Server
X-Ec-Fail
X-Ec-GeoHdr
X-Rojux
X-S-Cookie
X-Vdms-Path
X-Vdms-Version
X-Viewer-Country
X-Vtex-Remote-Cache
X-Varnish-Hostname
X-TIM-N
X-Scheme
X-ScT
X-SRCache-Key
X-Destination
X-D
Vix-Hermes-Req-Id
X-A
X-A-Ccd
X-A-Dam
Type
T-Server
Req-ID
Server-Host
Sslversion
Surrogated-Key
X-A-Dcw
X-A-Wwc
X-Bl-Debug
X-Cache-Bucket
X-Cache-NE
X-Conf
X-BCube-Filmed-By
X-Bc-Bl
X-Aed
X-Application
X-B-Cookie
Rendered-Blocks
X-Ec-Custom-Error
X-Correlation-ID
Expiry
X-TimeS
X-Request-URI
X-Dc
X-Connection-Hash
X-Mly-Id
X-Debug-Cache-Fetch
DSUID
X-NMSegId
Ssr
X-Debug-Cache-Store
Environment
X-Node-Id
X-Core-Value
X-Origin-Time
X-Esi-Check
Cluster
X-Nyt-Route
Content-Script-Type
X-Loc
Content-Style-Type
X-Human
NM-Fastcgi-Cache
Server-Ext
Release
X-Forwarded-Site
X-SB
Server-Hostname
Pramga
X-Fastly-Cache
X-Gdpr
X-Generated-On
X-Gzip
Host-ID
X-Level-Front-Cache
X-Op-Id-All
X-GeoIP-Region-Code
Sever-Int
X-GeoIP-Country-Code
Magicmarker
Fastly-GeoIP-CountryCode
CDCHOST
X-TH-Server
X-Thanos
V-Age
X-VServer
X-Cache-Id
X-Sigma-Backend
A
X-VG-WebCache
X-Varnishpool
X-Bip
X-VG-TLSProxy
X-Varnish-Director
X-Branch-Name
X-Varnish-Beresp-Status
X-SD-PageType
X-Sigma
X-Instance-Name
User-Cache-Control
X-Pubstack
X-Proxied-Request
X-Pool
X-We-Are-Hiring
X-Cache-Info
X-Clientip
X-Mg-Request-UUID
X-Rocket-Build-Number
X-Request-Time
X-WA-Info
X-TA-CDN-Provider
Fastly-Drupal-HTML
X-Service
X-Origin-Response-Time
X-Block-Status
X-BBC-Edge-Cache-Status
X-B3-Trace-ID
Wxu-Next-Hostname
Wxu-Next-Region
X-Acquia-Purge-Cdn-Unconfigured
X-Contensis-Viewer-Groups
X-Access
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Date
X-Device-Os
X-Cache-Aspx
Wxu-Next-Commit
X-DPWN-IS-SECURE
X-Micro-Cache
X-Server-IP
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
L
X-Request-Host
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-V-Cache
X-Var-Ttl
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Varnish-Authentication
C-Via
X-Policy
X-PERF
X-GoCache-CacheStatus
X-HS-Content-Campaign-Id
X-GeoIP-City
X-GeoIP
X-From
X-Geo-Header
X-Irp-Debug
X-Men
Req-Svc-Chain
X-Org
X-Old-Content-Length
X-Mvc-Supplant-OutputCached
X-Cache-TTL-Remaining
X-Mvc-Supplant-Cachable
X-FC-Vary-Parameters
X-Auto-Login
Uber-Trace-Id
Gh-Request-Id
Is-Eu
Fastly-SSL
Platform
We-Hiring
Esi-Enabled
Machine
X-NCache
On-Server
X-Section
Producers
X-Req
X-UA-Device-Type
Mail-Subject
X-Nginx-Cache-Key
X-Zen-Fury
X-Hnp-Log
Web-Mar-Region
Adler-Geo
X-Gen-Mode
X-Ad-Load-Variation
X-ApacheServer
Canary
Cache-Key
X-Slack-Backend
Country-Code
AKAMAI
X-Test
Yak-Timeinfo
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
Cdn-Host
Cdnsip
RNT-Machine
Cdncip
RNT-Time
Locid
Cf-Device-Type
X-AK-Request-ID
Cdn-Request-Time
X-Hash
X-App-Name
X-Fastly-Backend
X-Up
Click-Count-Action-Start
X-Proto
X-Moov-T
True-Client-Country-4JS
X-ND-Cache
Cache-Provider
X-Wikidot-Static-Cache
X-Aicache-OS
X-Wikidot-Backend
X-Cdn-Srv
X-Fmm-Version
X-Moov-Xdn-Version
Click-Count-Error
Tube-Got-Results
Tube-Get-Contents
X-Edge-Server
X-Region-Sid
Proxy-Firewall
Tube-Got-Eval
Tube-Return
X-Parent-Response-Time
X-Amz-Storage-Class
X-Accel-Expires-Debug
X-Owner
X-CacheTTL
X-Ah-Environment
NGX
X-Core-Mission
W
X-Date
X-Azure-Ref-OriginShield
Fastly-Backend-Name
X-ZONE
Pics-Label
X-Backend-Instance
X-VarnishDD-TTL
IsBot
X-Eu-Site
X-DC
X-HN
PFcat
X-Csrf-Jwt
X-CGP
X-COUNTRY
X-SIPLIST1
X-Via-Popn
L5d-Success-Class
X-LB-ID
X-HA-Backend
X-Via-Popv
X-Via-Poph
Ha-Gx-Prefs
HA-Ipaddr
X-NGINX-Cache
X-CACHE-GROUP
X-Qloud-Router
X-DynaTrace-JS-Agent
X-Ratelimit-Reset
LB
Datacenter
X-Origin-Expires
X-CF-Lambda-Fn
X-Tb-Optimization-Total-Bytes-Saved
X-CF-Lambda-Version
NtCoent-Length
N-Cache
Expect-Staple
XM
X-Refresh
X-Varnish-Hits
X-API-Version
X-Tx-Id
X-VHOST
Cdn
X-Lagoon
Xc-Version
X-Cache-Backend
X-LB-NoCache
X-Servedbyhost
X-Tenant
RATING
GeoIp-Country-Code
X-Forwarded-Path
X-Orig-Expires
X-Cache-Type
X-CDN-Cache-Status
X-Shop-Environment
Cdn-Requestid
X-ECache
X-Srv
Cmstype
Cmsid
X-Gamma-Serve
X-TX-ID
X-UA
X-Wa
Server-ID
X-Nc
SID
X-RID
CPC-Age
CPC-Cache
CloudFront-Viewer-Country
X-Nananana
Cross-Origin-Opener-Policy-Report-Only
X-Vmg-Version
X-Cdn-Diag
X-Zone
X-Akamai-Transformed
X-Hit
X-B3-Parentspanid
X-Fpc
X-Via-Fastly
Resin-Trace
X-Nf-Request-Id
X-Tt-Logid
User-Agent
X-Proxy-CacheRZ
Uri
Cache-Hits
XkeyRZ
DataCenter
X-Client-Ip
X-Ig-Origin-Region
CacheControlHeader
GeoIP-Latitude
X-Variation
X-LAGOON
X-Location
X-Presslabs-Stats
X-URL
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Component-Id
X-Amz-Meta-Opti
X-Fastly-Country-Code
Fusion-Source
X-TIME
Fusion-Template-Id
X-Api-Version
X-Info
Tcn
Fastly-Drupal-Html
True-Client-IP
Powered-By
True-Client-Ip
Mime-Version
Lb
X-Cloudmap
X-Datacenter
Cf-Ipcountry
X-NWS-UUID-VERIFY
X-B3-Spanid
X-HostName
X-NewRelic-App-Data
X-Cdn-Forward
Origin-EX
X-Jungle-Id
X-DataCenter
Origin-CC
X-CACHE-AGE
X-CS
MIME-Version
VNS-Age
VNS-Cache
X-CUA
X-Geo
X-Dynatrace-Js-Agent
X-LiteSpeed-Tag
Srv
X-Cached-By
X-IAuth-Set-Uid
X-User
X-Varnish-Beresp-TTL
X-Vc
X-HOST
X-Segment-20210421
Debug
Load-Balancing
X-LiteSpeed-Cache-Control
X-Dispatcher-Number
X-AIR-PT
CDN
X-Render-Time
Cache-Name
Hostname
X-Webkit-Csp-Report-Only
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Time
Cl-Cache
X-VTEX-Cache-Server
X-FPC
X-CSRF-TOKEN
Server-Id
X-MCACHE
X-Auth-Group-Type
Edge-Cache
X-Wormhole-Sdk
X-NC
GeoIP-Country-Code
Ohc-File-Size
X-WA
X-Dispatch
X-Esi
X-Mid
X-Litespeed-Tag
X-Ig-Push-State
X-Oracle-DMS-ECID
X-Cs
X-ServedByHost
X-Cdn-Cache-Status
X-Lb-Nocache
X-APP-VERSION
Ohc-Cache-HIT
BehaviorPad-Version
Odigeo-Trace-Id
X-Cache-Ttl
X-Vgn-Hpd-Reason
X-Cache-Enabled
X-Fastly-Backend-Reqs
CountryCode
X-Custom-Header
X-NodeID
Ms-Author-Via
X-Litespeed-Cache-Control
X-VCL-Version
X-MiniProfiler-Ids
X-Akamai-Pragma-Client-IP
Xkeylog
X-Cdn-Request-ID
X-Proxy-Cache-La3
X-Lb-Id
X-PHP-Backend
X-Depends
YJS-ID
X-MSEdge-Features
X-MSEdge-Flight
Server-Info
Xkey-La3
X-Pad
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Time
X-Acquia-Purge-Tags
X-Acquia-Site
X-FL-EDGE
Location
Srvid
My-App
X-FL-QIT-DEBUG
X-Ha-Backend
X-Via-PopN
FSS-Cache
OriginIP
X-IN-APIGATEWAY
Geoip-Latitude
X-Varnish-CookieHashed-On
X-DefHash
X-Snapshot-Date
Ngx
X-IN-APIGATEWAYSSL
X-Via-PopH
Memcached
Memory
X-Varnish-Remaining-TTL
X-Via-PopV
X-DefElseHash
X-Varnish-CookieINHashed-On
X-Sorting-Hat-Shopid
X-Shopid
X-Shardid
X-Cache-Version
X-Sorting-Hat-Podid
Cloudfront-Viewer-Country
PICS-Label
X-VC-TTL
Warning
X-M-Log
X-M-Reqid
X-Fastly-Cache-Hits
X-Sucuri-Id
X-Th-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
CF-Cached-On
X-Lsadc-Cache
CF-Ctrl
X-Internal-Host
X-RequestId
X-Udemy-Cache-App-Namespace
X-Web-Server
X-Dw-Trace-Id
X-Mg-Cache
X-Service-Response-Time
X-Serial
Sm-Log-Id
X-Check-Cacheable
Akamai-Cache-Status