Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-AspNet-Version
X-Runtime
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Ua-Compatible
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Vhost
X-Rq
X-Age
Xkey
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
X-Page-Speed
X-Pingback
Cf-Railgun
EagleEye-TraceId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
X-Dns-Prefetch-Control
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-CST
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Host
X-Response-Time
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-HW
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Ruxit-JS-Agent
X-Trace
Content-Location
X-Cache-Lookup
X-Url
Service-Worker-Allowed
X-Oneagent-Js-Injection
X-Content-Type
X-Country
X-Clacks-Overhead
X-ECACHE
X-Litespeed-Cache
X-Edge
X-Origin-Cache-Key
X-Mod-Pagespeed
Accept-Ch
X-Amz-Server-Side-Encryption
X-Midtier
X-FTR-Request-ID
X-Rack-Cache
Cross-Origin-Opener-Policy
Cache-Tag
X-Mcache
X-MS-InvokeApp
Nginx-Cache
X-Upstream
X-TtlSet
X-Vname
X-PC
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-D2id
X-Browser-Type
X-Element-Page-Cache
X-Kinja-Server
Verso
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Times
X-Server-Name
X-Cnection
X-Ac
SPIisLatency
SPRequestDuration
X-B3-TraceId
AR-Request-ID
AR-PoweredBy
AR-SID
AR-ATIME
X-Vcap-Request-Id
X-Navigation-Version
X-Ruxit-Js-Agent
X-Abt-Application-Version
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Dw-Request-Base-Id
X-RateLimit-Remaining
X-GitHub-Request-Id
X-VARITI-CCR
X-Ser
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
AR-CACHE
S
X-Cache-Key
X-Mg-S
RTSS
Origin-Trial
X-Client-IP
X-Cache-TTL
Edge-Cache-Tag
X-Middleton-Display
Display
Pagespeed
X-Sol
X-Amz-Rid
X-Amzn-Trace-Id
Fastly-Restarts
X-Goog-Hash
X-Powered-CMS
X-NWS-LOG-UUID
X-Ttl
X-Varnish-TTL
X-Content-Security-Policy-Report-Only
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-ID
X-Instrumentation
X-Version
Cache-Status
X-Edge-Location-Klb
X-Kinsta-Cache
Access-Control-Request-Method
X-Recruiting
X-ARC
X-Webkit-Csp
X-Content-Digest
Arr-Disable-Session-Affinity
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-TraceId
X-T
X-MSEdge-Ref
X-Forwarded-For
Response
X-Middleton-Response
X-Ua-Device
Content-MD5
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
MicrosoftSharePointTeamServices
X-Accel-Expires
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
Public-Key-Pins
X-FTR-Expires
X-Id
X-Request-Processing-Time
X-Request-Received
Server-Node
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
MS-Author-Via
Payment
X-Frontend
X-Ua-Browser
Front-End-Https
X-DIS-Request-ID
X-RateLimit-Limit
Cross-Origin-Resource-Policy
X-LLID
X-Forwarded-Proto
X-HP-Trace-Id
X-FastCGI-Cache
X-HP-Webp
X-Jurisdiction
X-GUploader-UploadID
X-WebKit-CSP-Report-Only
X-Fastcgi-Cache
X-Daa-Tunnel
Cache-Tags
TP-L2-Cache
X-LB-Cache
Realpath
X-Kinja-CCPA
X-Amz-Apigw-Id
X-Amzn-RequestId
X-ORACLE-DMS-RID
X-Protected-By
X-Origin-Server
X-Distributor
X-TTL
Count-Hit
X-Microsite
X-Request-Handler-Origin-Region
X-Page-Id
X-F-Cache
X-Cluster-Name
X-Activity-Id
X-PressLabs-Stats
X-Az
X-AppVersion
X-NGENIX-Cache
X-Www-Served-By
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Varnish-Backend
Accept-Charset
X-Geo-Country
Referer-Policy
X-Debug-Info
X-Correlation-Id
X-App-Server
X-Envoy-Decorator-Operation
X-Kong-Proxy-Latency
X-Goog-Metageneration
Host
X-Kong-Upstream-Latency
X-FB-Debug
X-Varnish-Server
X-ORACLE-DMS-ECID
Fastcgi-Cache
X-Hostname
Access-Control-Allow-Method
X-Git-Hash
X-Rid
X-RateLimit-Reset
Retry-After
X-XRDS-LOCATION
X-Ratelimit-Limit
X-TEC-API-ROOT
Server-Name
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Content-Options
X-Tt-Trace-Host
X-Load-Cache
X-Tt-Trace-Tag
X-Fastly-Request-ID
X-Px
DC
X-Route-Name
X-Is-Crawler
X-Request-Guid
X-Origin-Cache
X-Aspnet-Duration-Ms
X-Contextid
X-Flags
X-Providence-Cookie
X-CSRF-Token
X-B3-Sampled
X-Revision
X-App-Environment
X-Oracle-Dms-Ecid
X-Grace
X-Signature
X-B-Cache
X-Trace-Id
X-Type
X-Cache-Control
Cleartype
X-Mobile
X-Upgrade-Enabled
Paypal-Debug-Id
Charset
X-B
X-TT
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-ASPNET-VERSION
X-Datadog-Sampling-Priority
X-Fb-Rlafr
Section-Io-Cache
X-Amz-Meta-S3cmd-Attrs
X-Language
X-Seen-By
X-Amz-Replication-Status
Frame-Options
X-Ezoic-Cdn
TCN
X-Logged-In
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Whom
Filterid
X-Magnolia-Registration
Healthy
X-Wix-Request-Id
X-Oracle-Dms-Rid
X-Node-Name
X-EdgeConnect-Cache-Status
X-Newrelic-App-Data
X-Azure-Ref
X-App-Version
Content-Disposition
X-N
X-Proxy
Backend
X-Fastly-Request-Id
X-Varnish-Ttl
Akamai-GRN
X-Template
Upgrade-Insecure-Requests
Refresh
NGB
X-Air-Pt
X-Proxy-Cache-Info
X-Original-Request-Id
X-Response-Served-From
X-Rendered-As
X-Is-Bot
SD-X-WS
X-Page-View
X-Servername
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-B3-SpanId
X-Tumblr-Pixel-1
X-Unique-Id
X-Tumblr-User
VIX-Pulpo-Node
X-RemovedCookies
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-ProcessESI
X-Adobe-Loc
X-RTag
Url
Liferay-Portal
X-WP-CF-Super-Cache
X-Amzn-Remapped-Content-Length
Ms-Operation-Id
X-Debug-IsConnected
X-Debug-IsPreview
Viewport
X-WP-CF-Super-Cache-Cache-Control
X-Instance
X-Varnish-Grace
X-Datadog-Sampled
MS-CV
X-Adobe-Content
X-Debug
X-FW-Dynamic
X-UUID
X-FW-Hash
X-Ratelimit-Remaining
Fastly-SIE
Fastly-SWR
X-Cache-Grace
X-Region
X-User-Agent
X-IPS-LoggedIn
X-G
X-Cacheable-TTL
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Version
X-FW-Serve
From-Origin
X-NYM-Debug-Backend
X-Device-Type
X-L-Path
X-Jobs
X-Environment-Context
X-Cache-Hit
Country
X-Rule
X-Status
X-Hl-Ver
X-Backend-Name
X-Hosted-By
Surrogate-Key
X-Webkit-CSP
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
ServerID
X-Cache-Age
X-Http-Reason
X-Content-Powered-By
X-Time
X-VC-Cache
Protected
X-Cache-Status-Check
Alternate-Protocol
X-Akamai-Request-ID2
Countrycode
Amp-Access-Control-Allow-Source-Origin
X-Origin-TTL
X-NODE
X-Origin-CC
X-XRDS-Location
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Use-Magma
X-CCDN-Origin-Time
X-B3-Traceid
X-HTML-Minification-Powered-By
Version
X-INCAP-ABP
X-Via-JSL
X-Akamai-Edgescape
WPO-Cache-Message
WPO-Cache-Status
X-Tec-Api-Version
X-Rocket-Nginx-Serving-Static
X-Tec-Api-Root
X-Tec-Api-Origin
X-Framework
SRV
GEO-INFO
X-Edge-Location
X-WP-CF-Super-Cache-Active
X-Cache-Rule
CDN-RequestId
Front
X-Storage
X-Accel-Version
X-CDN-Forward
X-Source
Access-Control-Request-Headers
CF-IPCountry
X-Nginx-Cache
X-Httpd
X-Mode
X-Use-Mantle
X-Endurance-Cache-Level
Webserver
X-Upstream-Ht
OT-Force-Account-Verify
Filters
X-Xfnlog-Site
Accept-Language
X-VC
X-UPSTREAM-Address
Xet-Cookie
Meta-Geo
X-Upstream-Ct
X-Real-IP
X-Rn-Rsrv
X-Cache-Operation
X-Rewrite-Enabled
X-Timing-Wait
X-Proxy-Build
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-JoinUs
X-Director
X-Detected-As
X-Cache-Debug
X-Soup
X-Served-From
Selected-Fe
X-SaId
X-SayCDN-TTL
X-Cms-Context
X-Say-Cacheable
ServedBy
X-Say-TTL
X-Adobe-Source
X-BYPASS-REASON
X-Cache-Time
X-Sql-Count
X-Handled-By
X-ProxyCache-Status
X-Sql-Duration-Ms
X-Tncms
X-Worker
X-Redis-Cache
X-Lambda-Id
X-Loop
X-Varnish-Age
X-Varnish-Cache-Hits
X-ProxyCache-Key
DB-Nickname
X-GeoCountry
AMP-Access-Control-Allow-Source-Origin
Azure-Version
Azure-SiteName
X-Origin-Hint
X-No-Session
Azure-InstanceId
Azure-RegionName
Property-Id
Azure-SlotName
TWC-Connection-Speed
Webcakes-App-Name
Web-Mar-Node
Webcakes-App-Version
Webcakes-Region
X-RM-Cache-TTL
TWC-Privacy
TWC-Locale-Group
X-Server-W
X-GeoCode
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-S
X-PHP-Host
X-Labrador-Cache-Channel
X-Varnish-Beresp-Grace
X-Logging-Id
X-Skip-Cache
X-Format
X-RCS-CacheZone
X-Generation-Time
X-LJ-Flow-ID
Xserver
Mn-Server-Ip
X-DynaTrace
X-VCT
X-Cache-Server
X-Restarts
X-VWS-Id
X-IPLB-Request-ID
X-AWS-Id
X-Fetched-On
Apigw-Requestid
X-IPLB-Instance
X-ServerID
X-Forwarded-Host
X-Origin
X-Browser-Name
X-Routing-Service
X-Is-Desktop
X-AB
X-Frame-Option
X-Vercel-Cache
X-Cluster
X-Is-Mobile
X-Cache-Host
X-Vercel-Id
X-Is-Supported-Browser
X-Tcp-Rtt
X-Provided-By
X-Git-Commit
X-Is-Tablet
X-Ms-Request-Id
X-Proxied
Node
X-Extlb
X-COUNTRY
X-Reqid
X-Tb
X-Zipkin-Id
X-Geo-Region
X-Ms-Version
X-Container-Uri
X-Uri
Cache-Tv-Group
X-R9-Blue-Green-Version
Section-Io-Id
X-Locale
X-Site-Version
X-FB-TRIP-ID
X-Platform-Processor
Priority
X-Web-Node
X-Platform-Cluster
X-Platform-Router
Content-Secure-Policy
X-Vcache
X-Webstats-RespID
Source
X-Drupal-Cache-Tags
Cross-Origin-Embedder-Policy
X-Drupal-Cache-Contexts
Fastcgi-Useragent
X-Vcl-Version
WP-Super-Cache
X-MP-GENERATED-AT
X-Origin-Date
Onion-Location
CDN-Uid
CDN-RequestPullSuccess
WZWS-RAY
CDN-PullZone
CDN-Cache
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestCountryCode
CDN-RequestPullCode
X-Shopify-Stage
X-Urbn-Context-Path
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Urbn-Site-Id
Locale
X-Content-Age
X-SRV
S-Rt
X-Generated-By
X-Ua
X-Pass-Why
X-Newrelic-Synthetics
X-Sorting-Hat-PodId
X-Sucuri-Cache
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-TT-LOGID
X-Cdn-Origin
X-Sucuri-ID
X-Buckets
Sid
X-Proxy-Cache-Status
X-Cluster-Node
X-Cache-Action
X-Varnish-Beresp-Ttl
X-Mg-Request-UUID
X-Cache-Expired-At
Cross-Origin-Window-Policy
X-Xrds-Location
Cross-Origin-Embedder-Policy-Report-Only
X-VCache
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
TDXMobile
X-Scope-Id
X-Thinkindot-L3
Thinkindot-Control
X-Shield-Cache-Expires
X-CMSURLCustom
Fastly-Drupal-HTML
X-Datadome
X-LSADC-Cache
Cache
X-GEO
HostName
X-DataDome
X-Request-URI
X-Aspnetmvc-Version
X-Optimistic-Header
X-A-Ccd
X-A-Dam
CDCHOST
Surrogated-Key
X-Vdms-Path
X-Vdms-Version
Type
T-Server
X-A
X-Correlation-ID
Sslversion
Ngx.Var.Host
Environment
Gannett-Cam-Experience-Id
Lang
X-S-Cookie
DCR-Processing-Time-Ms
DCR-Decision-By
Candidate-Md5Url
X-ScT
X-Scheme
MD5-Digest
Meta-Geo-Continent
Origin-Agent-Cluster
Redirect-Candidate
Rendered-Blocks
Origin
X-SRCache-Key
X-Rojux
Ngx-Var-Key
X-A-Dcw
X-TIM-N
X-Viewer-Country
X-PAYTM-SRV-ID
X-A-Dgt
X-Cache-NE
X-Cache-Bucket
X-BCube-Filmed-By
X-Bl-Debug
X-D
X-Destination
X-Epic-Correlation-Id
X-External-Request-Id
X-Ec-GeoHdr
X-Ec-Fail
X-Developer
X-Ec-Custom-Error
X-Bc-Bl
X-Conf
X-A-Wwc
X-B-Cookie
X-Vtex-Remote-Cache
X-Aed
X-Application
Atl-Traceid
Edge-Copy-Time
X-WP-CF-Super-Cache-Cookies-Bypass
X-Via-CDN
X-Via-SSL
X-TimeS
X-Via-Edge
X-Generated-On
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Gdpr
X-Fastly-Cache
Magicmarker
X-Proxied-Request
X-Access
X-Forwarded-Site
Host-ID
X-Mly-Id
X-Men
X-Nyt-Route
X-SD-PageType
X-Node-Id
X-Section
X-Loc
X-Level-Front-Cache
L
X-Instance-Name
X-Dispatcher-Server
X-SB
X-Op-Id-All
X-Human
X-Debug-Cache-Store
Server-Host
Server-Hostname
X-Cache-Info
Server-Ext
X-Req
X-Platform
X-Pubstack
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Bip
Ssr
Sever-Int
X-Request-Start
X-Request-Time
X-Debug-Cache-Fetch
Pramga
Vix-Hermes-Req-Id
X-Acquia-Purge-Cdn-Unconfigured
X-Origin-Time
V-Age
Release
X-Aicache-OS
X-Pool
Req-Svc-Chain
Req-ID
X-Core-Value
X-Rocket-Build-Number
Fastly-GeoIP-CountryCode
X-Thanos
X-Up
X-TH-Server
X-Sigma-Backend
Apple-News-Services-Handled
X-Sigma
X-Varnish-Beresp-Status
X-Varnish-Director
X-VG-WebCache
X-VServer
X-VG-TLSProxy
X-Varnishpool
X-Varnish-Hostname
Apple-News-Services-Host
X-We-Are-Hiring
Apple-News-Services-Parsed-Url
X-Server-IP
Apple-News-Services-Request-Url
User-Cache-Control
X-Origin-Response-Time
X-Service
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Click-Count-Action-Start
Uber-Trace-Id
X-Core-Mission
Tube-Return
X-Device-Os
X-Fastly-Backend
X-FC-Vary-Parameters
X-Var-Ttl
X-Fmm-Version
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Canary
X-DPWN-IS-SECURE
X-Esi-Check
Click-Count-Error
X-PERF
DSUID
X-Clientip
X-Block-Status
X-Policy
X-Auto-Login
Esi-Enabled
X-Zen-Fury
X-Ad-Load-Variation
X-WA-Info
X-Cache-Date
We-Hiring
X-V-Cache
X-Cache-Id
Web-Mar-Region
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
X-Cache-TTL-Remaining
X-From
Machine
X-Irp-Debug
Adler-Geo
X-Org
Mail-Subject
X-ApacheServer
X-HS-Content-Campaign-Id
C-Via
X-Micro-Cache
Is-Eu
X-NMSegId
X-NCache
X-Nginx-Cache-Key
Fastly-SSL
Gh-Request-Id
X-Old-Content-Length
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-Hash
X-Hnp-Log
X-GeoIP
X-GeoIP-City
Producers
X-Geo-Header
X-Gen-Mode
X-UA-Device-Type
Country-Code
Cache-Provider
Platform
X-SVT-ORM-VERSION
NM-Fastcgi-Cache
X-Gzip
On-Server
X-SVT-ORM-RULES
X-DC
Cluster
X-HA-Backend
X-CacheTTL
X-Cdn-Srv
X-Request-Host
X-GoCache-CacheStatus
X-Edge-Server
X-ZONE
X-App-Name
X-Slack-Shared-Secret-Outcome
X-Via-Poph
X-Via-Popn
W
X-Slack-Backend
Cf-Device-Type
X-Sn-Servicetimems
True-Client-Country-4JS
X-Test
Proxy-Firewall
Pics-Label
X-Via-Popv
X-Proto
Cdn-Request-Time
IsBot
AKAMAI
Cdn-Host
X-SIPLIST1
X-TA-CDN-Provider
X-Parent-Response-Time
X-Connection-Hash
Expiry
X-Ah-Environment
X-Eu-Site
X-Amz-Meta-Cb-Modifiedtime
LB
Content-Style-Type
X-Branch-Name
Expect-Staple
HA-Ipaddr
Content-Script-Type
L5d-Success-Class
N-Cache
NGX
X-Dc
Ha-Gx-Prefs
Fastly-Backend-Name
A
X-CF-Lambda-Fn
X-Cache-Aspx
X-CF-Lambda-Version
X-Moov-T
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Csrf-Jwt
X-Moov-Xdn-Version
X-Wikidot-Static-Cache
X-Date
X-Wikidot-Backend
X-Owner
X-NGINX-Cache
X-Accel-Expires-Debug
X-CGP
Datacenter
X-Cache-Type
X-Qloud-Router
RNT-Machine
X-Tenant
X-Orig-Expires
Cache-Key
Xc-Version
X-Shop-Environment
X-Forwarded-Path
RNT-Time
X-Tt-Logid
Cdncip
X-LB-ID
Yak-Timeinfo
X-LB-NoCache
X-ND-Cache
Locid
X-AK-Request-ID
X-Region-Sid
Cdnsip
X-Gamma-Serve
X-Ratelimit-Reset
Cdn
PFcat
X-VarnishDD-TTL
X-Amz-Storage-Class
X-Refresh
X-Tx-Id
X-HN
X-Varnish-Hits
Cmsid
Cmstype
X-VHOST
SID
X-Vmg-Version
X-Servedbyhost
X-Tb-Optimization-Total-Bytes-Saved
X-Backend-Instance
NtCoent-Length
X-Wa
X-CDN-Cache-Status
X-DynaTrace-JS-Agent
GeoIp-Country-Code
X-Cdn-Diag
Server-ID
CPC-Cache
CPC-Age
RATING
X-Nc
Cdn-Requestid
X-Azure-Ref-OriginShield
X-LAGOON
X-Api-Version
X-TX-ID
X-API-Version
XM
X-Origin-Expires
X-Fpc
X-TIME
X-Srv
X-Akamai-Transformed
X-Via-Fastly
X-Nananana
CloudFront-Viewer-Country
X-Cache-Backend
CacheControlHeader
X-B3-Parentspanid
Resin-Trace
X-Lagoon
X-Variation
X-Hit
Tcn
X-HostName
X-Proxy-CacheRZ
XkeyRZ
X-Nf-Request-Id
Uri
X-CACHE-AGE
User-Agent
X-Client-Ip
X-Zone
Cross-Origin-Opener-Policy-Report-Only
X-URL
X-Fastly-Country-Code
X-LiteSpeed-Tag
X-NewRelic-App-Data
MIME-Version
X-Amz-Meta-Opti
X-Info
X-Datacenter
VNS-Age
X-LiteSpeed-Cache-Control
VNS-Cache
X-UA
Cache-Name
X-MCACHE
True-Client-IP
True-Client-Ip
Lb
X-Vc
X-Dynatrace-Js-Agent
DataCenter
Mime-Version
X-Location
X-Presslabs-Stats
X-DataCenter
X-CSRF-TOKEN
X-Geo
X-Ig-Origin-Region
GeoIP-Latitude
Hostname
Cache-Hits
X-AIR-PT
Cf-Ipcountry
Fusion-Content-Id
X-NWS-UUID-VERIFY
Fusion-Source
X-Dispatcher-Number
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Component-Id
X-B3-Spanid
Fastly-Drupal-Html
X-Cdn-Forward
Powered-By
X-Cached-By
Origin-EX
X-Jungle-Id
X-Mid
Origin-CC
X-CUA
X-Cloudmap
X-RID
X-Webkit-Csp-Report-Only
X-User
X-Segment-20210421
X-Varnish-Beresp-TTL
X-IAuth-Set-Uid
X-CS
Srv
BehaviorPad-Version
Ohc-File-Size
Debug
X-ECache
X-FPC
X-Render-Time
X-Dispatch
GeoIP-Country-Code
X-Esi
CDN
X-Litespeed-Tag
Ohc-Cache-HIT
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-NC
X-ServedByHost
X-Cdn-Cache-Status
Cl-Cache
X-Powered-By-VTEX-Cache
X-WA
Server-Id
Load-Balancing
X-Oracle-DMS-ECID
X-Cache-Enabled
X-Wormhole-Sdk
X-Cs
CountryCode
X-Lb-Id
YJS-ID
Edge-Cache
X-Lb-Nocache
My-App
Location
Server-Info
X-Auth-Group-Type
X-Snapshot-Date
X-Internal-Host
X-Fastly-Backend-Reqs
CF-Ctrl
X-Traceid
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Ms-Author-Via
X-ID
X-VCL-Version
Wpo-Cache-Message
X-Litespeed-Cache-Control
Wpo-Cache-Status
Xkeylog
Xkey-La3
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-MSEdge-Features
X-NodeID
X-Nitro-Rev
X-Ig-Push-State
X-Nitro-Cache
Section-Origin-Responded
X-Proxy-Cache-La3
X-MiniProfiler-Ids
X-Nitro-Cache-From
X-Akamai-Pragma-Client-IP
X-Cdn-Request-ID
X-App
CF-Cached-On
X-MSEdge-Flight
X-Dw-Trace-Id
X-IN-APIGATEWAY
OriginIP
X-IN-APIGATEWAYSSL
X-Acquia-Application-Trace
Time
Srvid
X-FL-EDGE
X-APP-VERSION
Memory
X-Acquia-Site
Ngx
Memcached
X-Cache-FS-Status
Geoip-Latitude
X-Acquia-Purge-Tags
FSS-Cache
X-Acquia-Application-UUID
X-FL-QIT-DEBUG
Odigeo-Trace-Id
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Shopid
X-Cache-Version
X-Shardid
Akamai-Cache-Status
X-Via-PopH
X-Ha-Backend
X-Te-Duration-Ms
X-Te-Count
X-Lsadc-Cache
X-Via-PopN
X-Vgn-Hpd-Reason
Cloudfront-Viewer-Country
X-Fastly-Cache-Hits
X-Via-PopV
X-Pad
X-Http-Duration-Ms
X-Udemy-Cache-App-Namespace
X-RequestId
X-Service-Response-Time
X-Serial
X-Check-Cacheable
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Th-Server
X-Http-Count
X-Web-Server
X-Mg-Cache
X-Sucuri-Id
Sm-Log-Id