Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Served-By
X-UA-Compatible
P3P
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
P3p
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
X-Ua-Compatible
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Allow
Cf-Edge-Cache
X-Backend
Request-Context
X-UA-Device
Keep-Alive
X-Robots-Tag
X-Cache-Group
X-Server
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-WebKit-CSP
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Readtime
X-Server-Id
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Nginx-Cache-Status
Accept-Ch-Lifetime
X-Node
X-Litespeed-Cache
X-Cache-Lookup
X-Application-Context
X-Country-Code
X-Trace
Content-Location
X-Ruxit-JS-Agent
X-Oneagent-Js-Injection
X-Country
Service-Worker-Allowed
X-Url
X-Content-Type
X-Clacks-Overhead
X-Origin-Cache-Key
X-Edge
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-ECACHE
Cross-Origin-Opener-Policy
X-Mcache
X-Midtier
Cache-Tag
X-Mod-Pagespeed
X-FTR-Request-ID
Accept-Ch
Nginx-Cache
X-MS-InvokeApp
X-PC
X-Vname
X-TtlSet
X-Upstream
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-Server-Name
X-Browser-Type
X-D2id
X-Element-Page-Cache
Verso
X-Times
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Cnection
X-Ac
SPRequestDuration
SPIisLatency
AR-PoweredBy
X-B3-TraceId
AR-ATIME
AR-SID
AR-Request-ID
X-Ruxit-Js-Agent
X-Abt-Application-Version
X-Navigation-Version
X-SharePointHealthScore
SPRequestGuid
X-Vcap-Request-Id
X-NF-Request-ID
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-Ser
X-NWS-LOG-UUID
AR-CACHE
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-VARITI-CCR
X-Mg-S
X-RateLimit-Remaining
S
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Client-IP
X-Ttl
X-Cache-Key
X-Server-ID
RTSS
Edge-Cache-Tag
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Powered-CMS
X-Cache-TTL
X-Goog-Hash
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Kinsta-Cache
Cache-Status
X-Edge-Location-Klb
X-Version
Access-Control-Request-Method
X-Recruiting
Origin-Trial
X-Varnish-TTL
X-ARC
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Content-Security-Policy-Report-Only
X-Content-Digest
X-TraceId
Response
X-Middleton-Response
Arr-Disable-Session-Affinity
X-Forwarded-For
X-Webkit-Csp
X-T
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-MD5
X-Accel-Expires
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
X-Daa-Tunnel
Public-Key-Pins
X-Id
Cross-Origin-Resource-Policy
Front-End-Https
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
MS-Author-Via
X-FTR-Backend
X-FTR-Expires
X-HS-Content-Id
X-Ua-Browser
X-HS-Combine-CSS
X-HS-Cache-Config
Server-Node
X-HS-Hub-Id
X-Request-Received
Payment
X-DIS-Request-ID
X-Request-Processing-Time
X-Frontend
X-Fastcgi-Cache
X-Forwarded-Proto
X-LLID
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-GUploader-UploadID
X-Protected-By
TP-L2-Cache
Realpath
X-FastCGI-Cache
X-LB-Cache
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-ORACLE-DMS-RID
X-Origin-Server
X-Distributor
X-RateLimit-Limit
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
X-Page-Id
X-AppVersion
X-Az
X-Hostname
X-Activity-Id
X-Ratelimit-Limit
X-Cluster-Name
Mrf-Cache-Status
MRF-Tech
X-F-Cache
X-B3-TraceId-Primal
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Backend
Referer-Policy
X-Debug-Info
X-Correlation-Id
X-Www-Served-By
X-Geo-Country
X-NGENIX-Cache
Fastcgi-Cache
Accept-Charset
X-Envoy-Decorator-Operation
X-App-Server
Host
X-PressLabs-Stats
X-Varnish-Server
X-Goog-Metageneration
X-ORACLE-DMS-ECID
X-Ua-Device
X-WebKit-CSP-Report-Only
X-FB-Debug
X-TTL
Access-Control-Allow-Method
X-XRDS-LOCATION
X-Git-Hash
X-Kinja-CCPA
Retry-After
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Fastly-Request-Id
X-Upgrade-Enabled
X-Load-Cache
X-RateLimit-Reset
X-CSRF-Token
X-Content-Options
Server-Name
X-Oracle-Dms-Ecid
X-Rid
X-Ezoic-Cdn
X-Px
X-Tt-Trace-Tag
X-Tt-Trace-Host
TCN
X-Contextid
X-Request-Guid
X-Revision
Charset
X-Seen-By
X-Trace-Id
DC
X-Datadog-Sampling-Priority
X-Cache-Control
X-Varnish-Ttl
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Amz-Meta-S3cmd-Attrs
X-Type
X-Grace
Paypal-Debug-Id
X-App-Environment
Cleartype
X-Signature
X-B-Cache
Section-Io-Cache
X-B3-Sampled
X-TT
X-Ratelimit-Remaining
X-B
X-Fb-Rlafr
Healthy
X-Oracle-Dms-Rid
X-Mobile
X-Whom
X-Wix-Request-Id
X-Origin-Cache
X-ASPNET-VERSION
X-Node-Name
X-EdgeConnect-Cache-Status
Frame-Options
X-Amz-Replication-Status
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
X-Flags
X-Newrelic-App-Data
X-Aspnet-Duration-Ms
X-Magnolia-Registration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Logged-In
X-Language
Filterid
X-Azure-Ref
X-Proxy
X-N
X-Fastly-Request-ID
X-Air-Pt
Content-Disposition
Backend
Akamai-GRN
X-WP-CF-Super-Cache-Cache-Control
X-NODE
X-WP-CF-Super-Cache
X-App-Version
Upgrade-Insecure-Requests
X-Template
X-Response-Served-From
NGB
X-Original-Request-Id
Refresh
X-Proxy-Cache-Info
X-Tumblr-User
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Rendered-As
X-Is-Bot
SD-X-WS
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Unique-Id
X-Instance
X-Servername
Liferay-Portal
X-Varnish-Grace
X-Datadog-Sampled
X-RTag
Viewport
Ms-Operation-Id
X-Amzn-Remapped-Content-Length
MS-CV
X-FW-Server
X-FW-Static
X-UUID
X-FW-Version
X-FW-Type
X-FW-Serve
X-FW-Dynamic
X-Debug
X-Debug-IsConnected
X-Debug-IsPreview
X-FW-Hash
X-IPS-LoggedIn
X-Cache-Grace
Fastly-SIE
X-Region
X-Cacheable-TTL
X-Adobe-Content
X-Adobe-Loc
X-User-Agent
Fastly-SWR
X-Time
X-Device-Type
From-Origin
X-Rule
X-G
X-Cache-Age
X-NYM-Debug-Backend
X-Hl-Ver
Url
X-Cache-Hit
X-Environment-Context
Country
X-L-Path
X-Backend-Name
X-Status
X-Jobs
ServerID
X-B3-SpanId
X-Page-View
X-CCDN-Origin-Time
Countrycode
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Via-JSL
X-Origin-TTL
X-VC-Cache
Surrogate-Key
X-Origin-CC
X-INCAP-ABP
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-Webkit-CSP
Amp-Access-Control-Allow-Source-Origin
X-Hosted-By
WPO-Cache-Message
WPO-Cache-Status
Alternate-Protocol
X-HTML-Minification-Powered-By
Version
X-Cache-Status-Check
X-Akamai-Request-ID2
X-Content-Powered-By
Protected
GEO-INFO
X-Rocket-Nginx-Serving-Static
X-Akamai-Edgescape
X-Nginx-Cache
CDN-RequestId
X-Source
SRV
X-B3-Traceid
X-Storage
X-Http-Reason
X-WP-CF-Super-Cache-Active
X-Framework
X-Accel-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-VC
X-Tec-Api-Version
X-Edge-Location
Access-Control-Request-Headers
Front
X-Cache-Rule
CF-IPCountry
X-CDN-Forward
OT-Force-Account-Verify
X-Real-IP
X-Mode
Meta-Geo
Filters
X-Httpd
X-Cache-Operation
Webserver
X-Xfnlog-Site
X-Rewrite-Enabled
X-Upstream-Ht
X-Rn-Rsrv
X-UPSTREAM-Address
X-Upstream-Ct
X-SaId
Accept-Language
X-Soup
Xet-Cookie
X-Served-From
X-Tumblr-Pixel-2
Selected-Fe
X-Proxy-Build
X-Endurance-Cache-Level
X-Director
X-Tumblr-Pixel-3
X-Timing-Wait
X-JoinUs
X-Worker
X-Use-Mantle
ServedBy
X-Logging-Id
X-Say-Cacheable
X-SayCDN-TTL
X-Handled-By
X-Web-Node
X-Redis-Cache
X-Say-TTL
X-Cache-Debug
X-Cache-Time
X-Origin
X-Varnish-Cache-Hits
X-Detected-As
X-BYPASS-REASON
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Webcakes-Region
X-GeoCountry
X-Format
X-RM-Cache-TTL
Azure-Version
X-Cms-Context
DB-Nickname
X-GeoCode
X-Tncms
X-Loop
X-PHP-Host
X-Server-W
X-No-Session
Xserver
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Locale-Group
X-Adobe-Source
X-Labrador-Cache-Channel
X-Origin-Hint
TWC-GeoIP-Country
Web-Mar-Node
X-VCT
X-Varnish-Age
X-ProxyCache-Key
X-Restarts
TWC-Connection-Speed
X-ProxyCache-Status
Webcakes-App-Name
Webcakes-App-Version
TWC-Device-Class
X-Lambda-Id
Property-Id
X-ServerID
X-DynaTrace
X-Fetched-On
X-Container-Uri
X-Generation-Time
X-Varnish-Beresp-Grace
X-AWS-Id
Apigw-Requestid
X-Git-Commit
X-Skip-Cache
X-IPLB-Instance
X-Vercel-Cache
X-RCS-CacheZone
X-Tb
X-Vercel-Id
X-VWS-Id
X-IPLB-Request-ID
X-LJ-Flow-ID
Section-Io-Id
X-Cache-Server
Mn-Server-Ip
Cross-Origin-Embedder-Policy
X-Locale
X-Frame-Option
X-Cluster
X-Cache-Host
X-Site-Version
X-Vcache
X-Reqid
X-Provided-By
Node
X-AB
X-Ms-Version
X-S
X-Geo-Region
X-Platform-Router
X-Is-Tablet
X-Is-Mobile
X-Browser-Name
X-Is-Supported-Browser
X-Is-Desktop
X-Ms-Request-Id
X-Proxied
X-Platform-Cluster
X-Platform-Processor
X-Extlb
AMP-Access-Control-Allow-Source-Origin
X-Forwarded-Host
X-Uri
X-Routing-Service
X-Tcp-Rtt
X-Zipkin-Id
X-Webstats-RespID
X-Xrds-Location
X-R9-Blue-Green-Version
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
Cache-Tv-Group
X-MP-GENERATED-AT
X-Sql-Count
X-TT-LOGID
X-Sql-Duration-Ms
WP-Super-Cache
Source
X-Origin-Date
Fastcgi-Useragent
CDN-PullZone
CDN-RequestPullSuccess
X-XRDS-Location
CDN-RequestPullCode
CDN-Uid
CDN-EdgeStorageId
CDN-Cache
CDN-RequestCountryCode
CDN-CachedAt
X-FB-TRIP-ID
X-Vcl-Version
Content-Secure-Policy
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Shopify-Stage
X-Sucuri-Cache
Priority
X-Use-Magma
X-Generated-By
Onion-Location
X-Sucuri-ID
X-Sorting-Hat-ShopId
X-ShardId
X-ShopId
X-Sorting-Hat-PodId
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Content-Age
X-Cdn-Origin
Sid
X-SRV
X-Newrelic-Synthetics
Cross-Origin-Embedder-Policy-Report-Only
S-Rt
X-Pass-Why
WZWS-RAY
X-Cluster-Node
X-Ua
X-Buckets
X-Shield-Cache-Expires
Thinkindot-Control
X-Thinkindot-L3
X-CMSURLCustom
X-DataDome
Thinkindot-CacheControl-Type
X-Scope-Id
Thinkindot-CacheControl
TDXMobile
Cross-Origin-Window-Policy
X-Proxy-Cache-Status
Cache
X-LSADC-Cache
X-Cache-Action
Atl-Traceid
X-Varnish-Beresp-Ttl
X-Cache-Expired-At
HostName
X-GEO
X-COUNTRY
X-Via-CDN
Edge-Copy-Time
X-WP-CF-Super-Cache-Cookies-Bypass
X-Via-Edge
X-Via-SSL
Type
X-Developer
X-A-Dcw
X-PAYTM-SRV-ID
X-A-Dam
X-Ec-Custom-Error
Fastly-Drupal-HTML
X-Ec-Fail
X-A
X-Vdms-Path
X-S-Cookie
X-A-Ccd
X-Rojux
X-Destination
X-Optimistic-Header
Origin-Agent-Cluster
Gannett-Cam-Experience-Id
Redirect-Candidate
DCR-Processing-Time-Ms
Origin
Lang
Meta-Geo-Continent
MD5-Digest
Ngx-Var-Key
Ngx.Var.Host
DCR-Decision-By
Rendered-Blocks
X-Epic-Correlation-Id
X-Viewer-Country
X-A-Dgt
X-Vdms-Version
X-External-Request-Id
T-Server
CDCHOST
Candidate-Md5Url
Sslversion
Surrogated-Key
X-Ec-GeoHdr
X-Request-URI
X-D
X-Bc-Bl
X-Cache-NE
X-Aed
X-SRCache-Key
X-Vtex-Remote-Cache
X-B-Cookie
X-Cache-Bucket
X-Application
X-ScT
X-BCube-Filmed-By
X-A-Wwc
X-Conf
X-TIM-N
X-Bl-Debug
X-Scheme
X-Mg-Request-UUID
X-Aspnetmvc-Version
X-Node-Id
User-Cache-Control
Server-Ext
Req-ID
X-Fastly-Cache
X-Nyt-Route
X-Loc
Apple-News-Services-Handled
Server-Hostname
Server-Host
Apple-News-Services-Request-Url
Ssr
X-Level-Front-Cache
Sever-Int
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Thanos
X-Generated-On
L
Host-ID
X-GeoIP-Country-Code
X-VCache
Magicmarker
X-Forwarded-Site
X-Clientip
X-TH-Server
Pramga
X-GeoIP-Region-Code
DSUID
Vix-Hermes-Req-Id
X-Human
Cluster
Environment
Release
Fastly-SSL
Fastly-GeoIP-CountryCode
X-Cache-Info
X-Instance-Name
X-VServer
X-Pubstack
V-Age
X-Proxied-Request
X-SD-PageType
X-Pool
X-Varnish-Director
X-SB
X-Section
X-Rocket-Build-Number
X-Gdpr
X-Op-Id-All
X-Request-Time
X-Debug-Cache-Store
X-Varnish-Beresp-Status
X-Dispatcher-Server
X-Varnish-Hostname
X-VG-WebCache
X-Sigma-Backend
X-Request-Start
X-Platform
X-Correlation-ID
X-Bip
X-Sigma
X-Varnishpool
X-Access
X-Origin-Time
X-We-Are-Hiring
X-Debug-Cache-Fetch
X-Datadome
Expiry
X-Origin-Response-Time
X-Connection-Hash
X-TimeS
X-ApacheServer
X-Acquia-Purge-Cdn-Unconfigured
X-Contensis-Viewer-Groups
Wxu-Next-Region
On-Server
Req-Svc-Chain
Uber-Trace-Id
X-Cache-Aspx
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Block-Status
True-Client-Country-4JS
X-Device-Os
X-FC-Vary-Parameters
Web-Mar-Region
Wxu-Next-Commit
We-Hiring
X-Cache-Date
X-Auto-Login
Wxu-Next-Hostname
X-Mvc-Supplant-OutputCached
X-SVT-ORM-VERSION
X-Zen-Fury
A
X-WA-Info
X-VG-TLSProxy
X-Gen-Mode
X-Request-Host
X-Cache-Id
X-PERF
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Req
X-SVT-ORM-RULES
X-Varnish-Authentication
X-Branch-Name
X-Esi-Check
Content-Script-Type
X-Server-IP
X-Core-Value
X-V-Cache
X-Gzip
X-UA-Device-Type
X-NMSegId
X-Mly-Id
X-Var-Ttl
X-Org
X-Policy
X-Irp-Debug
X-Men
X-TA-CDN-Provider
Canary
X-Geo-Header
X-HS-Content-Campaign-Id
Gh-Request-Id
X-GeoIP-City
X-GeoIP
X-Hnp-Log
X-Moov-T
Cache-Provider
X-NCache
X-Nginx-Cache-Key
Mail-Subject
NM-Fastcgi-Cache
X-GoCache-CacheStatus
Content-Style-Type
Machine
X-Mvc-Supplant-Cachable
X-Moov-Xdn-Version
C-Via
X-Service
Is-Eu
Producers
Platform
X-Test
X-Ad-Load-Variation
Esi-Enabled
X-Up
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Proto
X-Fastly-Backend
X-Fmm-Version
X-Hash
X-Cache-TTL-Remaining
X-Amz-Meta-Cb-Modifiedtime
X-Micro-Cache
X-From
Adler-Geo
X-Old-Content-Length
X-Cdn-Srv
X-DPWN-IS-SECURE
X-App-Name
Tube-Return
Click-Count-Action-Start
Country-Code
X-Aicache-OS
W
Tube-Got-Results
Cache-Key
Tube-Get-Contents
X-DC
X-Dc
AKAMAI
Tube-Got-Eval
Click-Count-Error
X-Parent-Response-Time
HA-Ipaddr
L5d-Success-Class
Ha-Gx-Prefs
X-ND-Cache
X-Sn-Servicetimems
Fastly-Backend-Name
Locid
X-Region-Sid
Cdnsip
Cdncip
X-AK-Request-ID
Yak-Timeinfo
RNT-Machine
RNT-Time
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-CacheTTL
Cf-Device-Type
X-Csrf-Jwt
Cdn-Request-Time
X-CGP
X-Ratelimit-Reset
Cdn-Host
X-Eu-Site
Proxy-Firewall
X-Edge-Server
X-Date
X-Core-Mission
IsBot
Pics-Label
X-Azure-Ref-OriginShield
X-VarnishDD-TTL
X-Owner
X-Amz-Storage-Class
PFcat
X-SIPLIST1
X-Ah-Environment
X-HN
X-Accel-Expires-Debug
X-Tx-Id
NGX
Datacenter
X-ZONE
LB
X-Via-Popn
X-Qloud-Router
X-HA-Backend
X-LB-ID
X-Via-Poph
X-Backend-Instance
X-Via-Popv
XM
X-CACHE-GROUP
Expect-Staple
X-Refresh
Cdn
X-Servedbyhost
N-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-CF-Lambda-Version
X-LB-NoCache
X-CF-Lambda-Fn
X-API-Version
X-Forwarded-Path
X-Cache-Type
X-Shop-Environment
NtCoent-Length
X-NGINX-Cache
Xc-Version
X-Tenant
X-Cache-Backend
X-Origin-Expires
X-DynaTrace-JS-Agent
X-Varnish-Hits
X-Orig-Expires
X-VHOST
X-Lagoon
GeoIp-Country-Code
X-Wa
X-Nc
SID
RATING
X-Gamma-Serve
X-CDN-Cache-Status
X-ECache
Cdn-Requestid
CloudFront-Viewer-Country
Cmstype
Cmsid
CPC-Cache
Server-ID
X-Srv
CPC-Age
Resin-Trace
X-Nananana
X-Cdn-Diag
X-Vmg-Version
X-Zone
X-Tt-Logid
X-Akamai-Transformed
Cross-Origin-Opener-Policy-Report-Only
X-TX-ID
X-Fpc
X-Via-Fastly
X-UA
X-Hit
Uri
X-LAGOON
User-Agent
X-TIME
X-Proxy-CacheRZ
XkeyRZ
GeoIP-Latitude
X-B3-Parentspanid
X-Nf-Request-Id
Cache-Hits
CacheControlHeader
X-Client-Ip
X-RID
X-Api-Version
X-Variation
X-Ig-Origin-Region
X-URL
X-Location
X-Presslabs-Stats
X-NewRelic-App-Data
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Deployment-Id
X-Amz-Meta-Opti
X-DataCenter
X-Info
X-Fastly-Country-Code
MIME-Version
True-Client-Ip
Fusion-Source
DataCenter
Fusion-Template-Id
Tcn
VNS-Cache
VNS-Age
X-Cloudmap
X-Datacenter
Lb
True-Client-IP
Powered-By
X-CACHE-AGE
X-B3-Spanid
X-NWS-UUID-VERIFY
X-Dynatrace-Js-Agent
X-HostName
X-Geo
Mime-Version
Origin-EX
X-CS
X-CUA
Fastly-Drupal-Html
X-Jungle-Id
Origin-CC
X-LiteSpeed-Tag
X-Cached-By
X-IAuth-Set-Uid
Cf-Ipcountry
X-LiteSpeed-Cache-Control
X-User
Hostname
Cache-Name
X-Webkit-Csp-Report-Only
X-Cdn-Forward
X-HOST
Debug
X-Vc
X-Segment-20210421
Srv
X-Varnish-Beresp-TTL
X-CSRF-TOKEN
Load-Balancing
X-AIR-PT
Cl-Cache
X-Render-Time
X-Dispatcher-Number
X-VTEX-Cache-Server
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Time
CDN
GeoIP-Country-Code
X-Mid
X-MCACHE
X-FPC
Edge-Cache
X-Auth-Group-Type
X-Wormhole-Sdk
Ohc-File-Size
X-Esi
X-Cdn-Cache-Status
X-Dispatch
Server-Id
X-Litespeed-Tag
BehaviorPad-Version
X-Ig-Push-State
X-Oracle-DMS-ECID
X-NC
X-WA
X-Cs
Ohc-Cache-HIT
Odigeo-Trace-Id
X-APP-VERSION
X-NodeID
X-Lb-Nocache
X-ServedByHost
X-Cache-Ttl
X-Cache-Enabled
X-Custom-Header
X-Vgn-Hpd-Reason
X-Lb-Id
X-Fastly-Backend-Reqs
CountryCode
YJS-ID
Ms-Author-Via
X-Litespeed-Cache-Control
X-VCL-Version
Xkey-La3
Xkeylog
Server-Info
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-Proxy-Cache-La3
X-Snapshot-Date
X-PHP-Backend
X-Cdn-Request-ID
X-MSEdge-Features
My-App
Location
X-Akamai-Pragma-Client-IP
X-Ha-Backend
X-MSEdge-Flight
X-Depends
X-MiniProfiler-Ids
X-Pad
X-DefHash
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Memory
Memcached
X-DefElseHash
X-Acquia-Site
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
Time
X-Acquia-Application-Trace
CF-Ctrl
X-FL-QIT-DEBUG
FSS-Cache
CF-Cached-On
X-FL-EDGE
Srvid
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Ngx
X-Internal-Host
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
OriginIP
X-Sorting-Hat-Shopid
X-Shardid
X-Shopid
Wpo-Cache-Message
X-Sorting-Hat-Podid
X-Cache-Version
Wpo-Cache-Status
Sm-Log-Id
X-Web-Server
PICS-Label
X-M-Log
X-M-Reqid
Warning
X-Serial
X-Service-Response-Time
X-Fastly-Cache-Hits
Akamai-Cache-Status
X-Dw-Trace-Id
X-Th-Server
X-Sucuri-Id
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-App
X-RequestId
Geoip-Latitude
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Nitro-Cache
X-Nitro-Cache-From
X-Udemy-Cache-App-Namespace
X-Check-Cacheable
X-Lsadc-Cache
X-Mg-Cache
Section-Io-Origin-Status
X-Nitro-Rev