Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
P3p
X-Drupal-Cache
Accept-CH-Lifetime
X-Cache-Status
X-DNS-Prefetch-Control
X-Generator
X-Check
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
X-Request-ID
Feature-Policy
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Cf-Edge-Cache
X-Backend
X-UA-Device
Keep-Alive
Request-Context
X-Robots-Tag
X-Server
Allow
X-Cache-Group
EagleId
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Dns-Prefetch-Control
Xkey
X-Age
X-Rq
X-Vhost
X-Amz-Version-Id
X-Dispatcher
X-Server-Powered-By
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-Pingback
Permissions-Policy
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-LiteSpeed-Cache
X-Device
Cf-Railgun
X-OneAgent-JS-Injection
EagleEye-TraceId
X-WebKit-CSP
X-Backend-Server
X-CST
X-Cache-Lookup
X-Host
X-Aws-Lambda-Call-Status
X-Server-Id
X-Readtime
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Litespeed-Cache
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
Content-Location
X-Country-Code
X-Ruxit-JS-Agent
X-Country
Service-Worker-Allowed
X-Trace
X-Url
X-Content-Type
X-Clacks-Overhead
Accept-Ch-Lifetime
Rating
X-Rack-Cache
Cache-Tag
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
X-Oneagent-Js-Injection
Cross-Origin-Opener-Policy
X-TtlSet
X-Vname
X-PC
Nginx-Cache
X-Origin-Cache-Key
X-Edge
X-Mcache
X-Midtier
X-NWS-LOG-UUID
X-MS-InvokeApp
X-Times
X-Mod-Pagespeed
X-Upstream
X-Server-Name
X-Powered-By-Plesk
X-ECACHE
X-Browser-Type
Edge-Control
X-ESI
X-Cnection
X-D2id
X-Cdn-Fetch
X-Exp-Id
X-Element-Page-Cache
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
Verso
X-Ser
AR-Request-ID
AR-ATIME
AR-PoweredBy
AR-SID
SPIisLatency
SPRequestDuration
X-Ac
SPRequestGuid
X-SharePointHealthScore
X-GitHub-Request-Id
X-Abt-Application-Version
X-B3-TraceId
X-NF-Request-ID
X-Navigation-Version
X-RateLimit-Remaining
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-Ttl
AR-CACHE
X-Ruxit-Js-Agent
X-Mg-S
Pagespeed
X-Sol
X-Middleton-Display
X-Client-IP
Display
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
Edge-Cache-Tag
S
Fastly-Restarts
X-Cache-Key
X-VARITI-CCR
X-Kraken-Loop-Name
X-Daa-Tunnel
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
X-Server-Lifecycle-Phase
X-Cache-TTL
X-Amz-Rid
X-Amzn-Trace-Id
RTSS
Cache-Status
X-Powered-CMS
X-Edge-Location-Klb
X-Kinsta-Cache
X-Version
X-Server-ID
Access-Control-Request-Method
X-Goog-Hash
Response
X-Middleton-Response
X-Recruiting
X-Webkit-Csp
X-Content-Digest
X-Varnish-TTL
X-TraceId
X-ARC
X-Forwarded-For
X-T
X-FastCGI-Cache
X-MSEdge-Ref
Arr-Disable-Session-Affinity
Cross-Origin-Resource-Policy
MS-Author-Via
Content-MD5
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Front-End-Https
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-Accel-Expires
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-FTR-Backend-Server
X-Forwarded-Proto
X-Cached
X-Hits
X-Ua-Browser
X-HS-Cache-Config
X-HS-Content-Id
X-Id
X-HS-Hub-Id
Realpath
X-HS-Combine-CSS
X-Request-Processing-Time
X-Request-Received
Public-Key-Pins
Server-Node
X-FTR-Expires
X-Frontend
Payment
X-Protected-By
X-LLID
X-Fastly-Request-ID
X-DIS-Request-ID
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Content-Security-Policy-Report-Only
X-Distributor
X-RateLimit-Limit
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Correlation-Id
X-ORACLE-DMS-RID
X-GUploader-UploadID
TP-L2-Cache
X-LB-Cache
X-Microsite
Cache-Tags
X-Request-Handler-Origin-Region
Fastcgi-Cache
X-Debug-Info
Count-Hit
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Envoy-Decorator-Operation
Referer-Policy
MRF-Tech
X-B3-TraceId-Primal
X-Az
X-AppVersion
X-Activity-Id
Mrf-Cache-Status
Host
X-Hostname
X-NGENIX-Cache
X-Cluster-Name
X-Page-Id
X-Origin-Server
X-Varnish-Backend
X-Www-Served-By
X-Geo-Country
X-Varnish-Server
Accept-Charset
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Ratelimit-Limit
X-App-Server
X-Fastcgi-Cache
X-Ezoic-Cdn
X-ORACLE-DMS-ECID
X-F-Cache
X-XRDS-LOCATION
Retry-After
Origin-Trial
X-PressLabs-Stats
X-Px
X-Load-Cache
X-FB-Debug
X-Goog-Metageneration
X-CSRF-Token
X-Seen-By
X-Upgrade-Enabled
Server-Name
X-Amz-Meta-S3cmd-Attrs
TCN
Access-Control-Allow-Method
Cleartype
X-Git-Hash
X-RateLimit-Reset
X-Webkit-CSP
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Varnish-Ttl
Section-Io-Cache
X-Grace
X-Request-Guid
X-Cache-Control
X-TT
X-Azure-Ref
X-B
X-Contextid
X-Trace-Id
X-B3-Sampled
X-Revision
X-Oracle-Dms-Ecid
X-Type
Healthy
X-Whom
Paypal-Debug-Id
DC
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
Charset
X-Proxy
X-Fb-Rlafr
X-Content-Options
X-Wix-Request-Id
X-Mobile
X-Newrelic-App-Data
X-Air-Pt
X-B-Cache
X-N
X-Signature
Accept-Ch
X-App-Environment
X-Node-Name
X-Oracle-Dms-Rid
X-Ratelimit-Remaining
X-CCDN-Origin-Time
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Magnolia-Registration
Filterid
X-Amz-Replication-Status
Frame-Options
X-Goog-Stored-Content-Encoding
X-Origin-Cache
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-EdgeConnect-Cache-Status
X-Time
X-Logged-In
X-TTL
Viewport
NGB
X-Unique-Id
X-Debug
Backend
Content-Disposition
X-Response-Served-From
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Debug-IsConnected
X-Cache-Grace
X-Tumblr-Pixel-1
X-Rendered-As
X-Debug-IsPreview
X-Is-Bot
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-RemovedCookies
X-ProcessESI
X-Tumblr-User
X-G
Liferay-Portal
Fastly-SWR
Fastly-SIE
X-FW-Server
X-FW-Static
SD-X-WS
Ms-Operation-Id
MS-CV
X-Adobe-Content
X-Varnish-Grace
X-Servername
X-Datadog-Sampled
X-FW-Version
X-FW-Type
X-FW-Dynamic
X-FW-Serve
X-FW-Hash
X-RTag
X-Adobe-Loc
X-IPS-LoggedIn
X-NYM-Debug-Backend
X-Ua-Device
X-Hl-Ver
X-Backend-Name
X-Amzn-Remapped-Content-Length
X-UUID
X-Instance
X-VC-Cache
X-Device-Type
X-Cacheable-TTL
ServerID
From-Origin
X-Cache-Age
Upgrade-Insecure-Requests
X-L-Path
X-Environment-Context
X-Via-JSL
X-Region
Akamai-GRN
X-Proxy-Cache-Info
X-User-Agent
X-Rule
Version
X-Cache-Hit
X-WebKit-CSP-Report-Only
Country
X-Status
X-B3-SpanId
Refresh
CDN-RequestId
X-Source
X-Template
X-INCAP-ABP
Countrycode
GEO-INFO
SRV
X-Rid
X-Language
Url
X-Storage
X-HTML-Minification-Powered-By
X-NODE
X-Air-Trace-Id
X-Air-Source
X-Cache-Status-Check
Alternate-Protocol
X-Air-Hostname
X-WP-CF-Super-Cache-Active
OT-Force-Account-Verify
X-Origin-CC
X-Origin-TTL
Amp-Access-Control-Allow-Source-Origin
X-Fastly-Request-Id
X-B3-Traceid
X-Real-IP
X-App-Version
WPO-Cache-Status
WPO-Cache-Message
X-ServerID
X-Is-Crawler
X-CDN-Forward
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Providence-Cookie
X-Jobs
X-Akamai-Request-ID2
X-VC
Surrogate-Key
Access-Control-Request-Headers
X-Content-Powered-By
X-Sucuri-Cache
X-Cache-Time
Protected
X-TT-LOGID
AMP-Access-Control-Allow-Source-Origin
X-Handled-By
X-Mode
Xet-Cookie
X-Sucuri-ID
X-Nginx-Cache
X-Rocket-Nginx-Serving-Static
X-Accel-Version
Filters
X-Rn-Rsrv
Webserver
X-Endurance-Cache-Level
X-Xfnlog-Site
X-Rewrite-Enabled
X-UPSTREAM-Address
X-Hosted-By
Meta-Geo
X-Akamai-Edgescape
X-Tumblr-Pixel-3
X-PHP-Host
X-Upstream-Ht
X-Cache-Rule
X-Worker
X-SaId
X-Upstream-Ct
X-Origin
X-JoinUs
X-Labrador-Cache-Channel
ServedBy
X-LJ-Flow-ID
Selected-Fe
Section-Io-Id
X-Drupal-Cache-Tags
X-Timing-Wait
X-Cache-Debug
X-Tumblr-Pixel-2
X-Cache-Operation
X-AWS-Id
X-VWS-Id
X-GeoCode
X-Detected-As
X-Edge-Location
Cross-Origin-Embedder-Policy
X-RM-Cache-TTL
X-Adobe-Source
X-Webstats-RespID
X-Proxy-Build
X-Web-Node
X-GeoCountry
TWC-GeoIP-LatLong
Webcakes-Region
TWC-GeoIP-Country
Webcakes-App-Version
X-Director
X-Extlb
TWC-Device-Class
TWC-Connection-Speed
TWC-Locale-Group
Mn-Server-Ip
Web-Mar-Node
X-Cms-Context
Atl-Traceid
Property-Id
Node
Webcakes-App-Name
X-Drupal-Cache-Contexts
TWC-Privacy
Front
X-Proxied
X-Routing-Service
X-Say-Cacheable
X-Redis-Cache
X-Cluster
X-Platform-Processor
X-Platform-Router
X-Framework
X-Say-TTL
X-Vcache
X-Zipkin-Id
X-Varnish-Cache-Hits
X-Soup
X-SayCDN-TTL
X-Served-From
X-Platform-Cluster
X-Restarts
X-No-Session
X-Logging-Id
X-Origin-Hint
X-Site-Version
X-Is-Supported-Browser
X-Skip-Cache
X-Is-Tablet
X-Is-Mobile
X-Is-Desktop
X-Geo-Region
X-Forwarded-Host
X-Tb
X-Lambda-Id
X-Tncms
X-Browser-Name
X-BYPASS-REASON
X-Locale
Xserver
X-AB
X-VCT
CDN-Uid
X-Varnish-Age
X-Loop
X-Tcp-Rtt
X-S
CDN-RequestPullSuccess
X-IPLB-Instance
CDN-Cache
X-RCS-CacheZone
Apigw-Requestid
X-ProxyCache-Key
X-ProxyCache-Status
CDN-CachedAt
X-IPLB-Request-ID
CDN-PullZone
X-Origin-Date
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-EdgeStorageId
Azure-RegionName
Azure-InstanceId
X-Varnish-Beresp-Grace
X-Vercel-Cache
X-Alternate-Cache-Key
X-Container-Uri
Azure-SiteName
X-R9-Blue-Green-Version
X-Generation-Time
Azure-SlotName
X-Cdn-Origin
X-Reqid
X-Fetched-On
X-Git-Commit
X-Shopify-Stage
X-Vercel-Id
X-Cache-Host
X-Format
X-Storefront-Renderer-Rendered
Azure-Version
X-Httpd
X-Provided-By
Accept-Language
X-Frame-Option
X-Ms-Version
X-Ms-Request-Id
X-Cache-Server
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-ShopId
Fastcgi-Useragent
X-RID
X-SRV
DB-Nickname
X-XRDS-Location
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
CF-IPCountry
X-Server-W
WP-Super-Cache
X-Azure-Ref-OriginShield
Source
X-Vcl-Version
Cross-Origin-Window-Policy
X-Uri
X-MP-GENERATED-AT
X-Page-View
Cross-Origin-Embedder-Policy-Report-Only
X-Generated-By
Thinkindot-Control
X-Shield-Cache-Expires
Thinkindot-CacheControl-Type
X-Scope-Id
X-Thinkindot-L3
TDXMobile
X-Xrds-Location
Thinkindot-CacheControl
X-CMSURLCustom
Cache
Cache-Tv-Group
X-UA
X-Pass-Why
X-FB-TRIP-ID
X-DataDome
X-Buckets
Content-Secure-Policy
Sid
X-PDP-UNCACHING-HASH
X-Lagoon
X-LSADC-Cache
X-Optimistic-Header
HostName
Onion-Location
X-Use-Mantle
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-Content-Age
X-GEO
X-Http-Reason
X-WP-CF-Super-Cache-Cookies-Bypass
Priority
X-DynaTrace
X-Request-URI
User-Cache-Control
Locid
X-Dc
Expiry
X-Connection-Hash
X-ND-Cache
X-TA-CDN-Provider
X-Aed
Meta-Geo-Continent
Origin-Agent-Cluster
X-Vtex-Remote-Cache
X-D
X-Destination
X-Bl-Debug
X-BCube-Filmed-By
X-Viewer-Country
X-Request-Start
A
X-UA-Device-Type
X-Varnish-Beresp-Ttl
X-Cluster-Node
Cdnsip
X-SB
X-S-Cookie
X-Rojux
X-Bc-Bl
X-SRCache-Key
X-ScT
Sslversion
Candidate-Md5Url
X-Cache-NE
X-Conf
Origin
X-Application
X-TIM-N
Cdncip
X-B-Cookie
X-AK-Request-ID
X-Cache-Bucket
X-A-Dcw
Gannett-Cam-Experience-Id
T-Server
Ngx-Var-Key
X-Op-Id-All
X-Vdms-Path
Req-ID
X-A-Ccd
X-A
X-Kinja-CCPA
X-Developer
Surrogated-Key
X-Platform
Server-Hostname
Magicmarker
Sever-Int
MD5-Digest
Server-Host
LB
X-Varnish-Hostname
Vix-Hermes-Req-Id
Lang
Server-Ext
Redirect-Candidate
Rendered-Blocks
X-Vdms-Version
X-Zen-Fury
X-A-Dgt
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Ec-Fail
Ngx.Var.Host
X-Dispatcher-Server
X-A-Wwc
DCR-Processing-Time-Ms
DCR-Decision-By
X-External-Request-Id
X-A-Dam
X-Proxy-Cache-Status
X-Newrelic-Synthetics
NM-Fastcgi-Cache
Cluster
Environment
C-Via
Content-Style-Type
Content-Script-Type
X-Origin-Expires
CDCHOST
V-Age
X-Ad-Load-Variation
X-Amz-Meta-Cb-Modifiedtime
DSUID
Wxu-Next-Hostname
Adler-Geo
X-B3-Trace-ID
Fastly-SSL
Wxu-Next-Commit
X-Req
X-Auto-Login
Is-Eu
Host-ID
X-Pubstack
Wxu-Next-Region
X-WA-Info
X-Fastly-Cache
X-Loc
X-Origin-Time
Release
True-Client-Country-4JS
X-Forwarded-Site
X-Esi-Check
X-Sql-Count
X-Ec-Custom-Error
X-DPWN-IS-SECURE
XM
Yak-Timeinfo
X-Sql-Duration-Ms
X-Gdpr
X-Varnishpool
X-Varnish-Authentication
X-Hnp-Log
X-PAYTM-SRV-ID
X-Level-Front-Cache
X-Cache-Action
X-Gzip
X-GeoIP-Region-Code
X-Generated-On
X-Gen-Mode
X-GeoIP
X-GeoIP-City
X-GeoIP-Country-Code
X-Bip
Producers
Platform
X-Cache-TTL-Remaining
X-Device-Os
X-Node-Id
X-Cache-Id
X-Cache-Aspx
X-Scheme
Cache-Hits
X-SD-PageType
X-Block-Status
Pramga
X-Nyt-Route
X-Datadome
X-Debug-Cache-Fetch
X-NCache
X-Contensis-Viewer-Groups
X-Core-Value
X-Thanos
X-Nginx-Cache-Key
X-Clientip
X-NMSegId
X-Debug-Cache-Store
Fastly-Drupal-HTML
X-Origin-Response-Time
X-Service
Uber-Trace-Id
Tube-Got-Results
Tube-Get-Contents
Tube-Return
Tube-Got-Eval
Ssr
X-Old-Content-Length
X-Mly-Id
X-Geo-Header
X-From
X-Moov-T
X-Fmm-Version
X-Moov-Xdn-Version
X-GoCache-CacheStatus
X-HN
X-Instance-Name
X-Men
X-Micro-Cache
X-Human
X-HS-Content-Campaign-Id
X-FC-Vary-Parameters
X-Mvc-Supplant-Cachable
X-Acquia-Purge-Cdn-Unconfigured
X-Amz-Storage-Class
X-Access
Web-Mar-Region
We-Hiring
X-ApacheServer
X-Backend-Instance
X-Cache-Info
X-Cdn-Srv
X-Cache-Expired-At
X-Cache-Backend
X-BBC-Edge-Cache-Status
X-Org
X-Region-Sid
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Handled
X-Request-Host
X-Request-Time
Cache-Provider
Canary
X-Varnish-Director
Country-Code
X-RateLimit-Remaining-Second
Click-Count-Error
Click-Count-Action-Start
X-Section
X-VarnishDD-TTL
X-We-Are-Hiring
X-TH-Server
X-Aicache-OS
X-VG-TLSProxy
X-VG-WebCache
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Server-IP
X-Sn-Servicetimems
X-ECache
RNT-Time
X-RateLimit-Limit-Second
Apple-News-Services-Host
X-Proxied-Request
PFcat
Machine
Mail-Subject
Req-Svc-Chain
L
X-V-Cache
Gh-Request-Id
X-Pool
X-Varnish-Beresp-Status
RNT-Machine
Esi-Enabled
Fastly-GeoIP-CountryCode
X-Var-Ttl
X-PERF
On-Server
X-Policy
X-NWS-UUID-VERIFY
X-API-Version
X-Fastly-Backend
X-CGP
X-Test
X-Eu-Site
X-VServer
X-Wikidot-Static-Cache
X-Mvc-Supplant-OutputCached
X-Edge-Server
X-Csrf-Jwt
X-Ratelimit-Reset
X-Wikidot-Backend
Proxy-Firewall
X-Slack-Backend
HA-Ipaddr
Ha-Gx-Prefs
X-Up
W
AKAMAI
Cache-Key
X-App-Name
X-Proto
Cf-Device-Type
Cdn-Request-Time
Cdn-Host
X-Rocket-Build-Number
L5d-Success-Class
X-DC
X-Slack-Shared-Secret-Outcome
X-Sigma-Backend
X-Cache-Date
X-Hash
X-Sigma
X-Tx-Id
WZWS-RAY
X-LB-ID
X-Ah-Environment
X-Via-Fastly
X-Cloudmap
X-Date
X-NGINX-Cache
X-CacheTTL
X-Tb-Optimization-Total-Bytes-Saved
X-Accel-Expires-Debug
NGX
X-Mg-Request-UUID
X-Zone
X-Branch-Name
Fastly-Backend-Name
X-COUNTRY
X-VCache
X-Via-SSL
X-CACHE-GROUP
X-Location
X-Ig-Origin-Region
X-DynaTrace-JS-Agent
X-Servedbyhost
X-HA-Backend
X-Via-Edge
X-Via-CDN
X-Via-Popv
NtCoent-Length
Pics-Label
X-Parent-Response-Time
X-Via-Poph
X-Via-Popn
Edge-Copy-Time
X-Varnish-Hits
S-Rt
Datacenter
X-Correlation-ID
Fusion-Component-Id
X-Refresh
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Deployment-Id
Type
Fusion-Template-Id
Cdn
X-VHOST
SID
X-Akamai-Transformed
X-Jungle-Id
X-CDN-Cache-Status
X-LB-NoCache
GeoIp-Country-Code
X-Esi
Resin-Trace
X-CUA
Origin-CC
Powered-By
Origin-EX
X-Ua
X-Wormhole-Sdk
X-User
X-Wa
X-Irp-Debug
X-Nc
X-ZONE
X-Presslabs-Stats
Server-ID
X-Owner
X-Core-Mission
GeoIP-Latitude
IsBot
Cross-Origin-Opener-Policy-Report-Only
X-Hit
X-Render-Time
X-SIPLIST1
X-Fpc
X-TX-ID
Cf-Ipcountry
X-LiteSpeed-Tag
X-NewRelic-App-Data
X-VTEX-Cache-Time
X-Srv
X-VTEX-Cache-Server
Cdn-Requestid
XkeyRZ
Debug
CloudFront-Viewer-Country
X-Qloud-Router
X-Powered-By-VTEX-Cache
X-B3-Parentspanid
X-Nf-Request-Id
X-Cached-By
X-Proxy-CacheRZ
X-Nananana
X-Client-Ip
DataCenter
X-DataCenter
Uri
X-URL
X-IAuth-Set-Uid
X-Segment-20210421
Edge-Cache
X-CS
Mime-Version
X-Cs
Expect-Staple
True-Client-IP
X-Amz-Meta-Opti
X-Auth-Group-Type
X-TIME
X-CF-Lambda-Version
X-CF-Lambda-Fn
N-Cache
Fastly-Drupal-Html
X-Cache-Type
X-Shop-Environment
X-Tenant
X-Ig-Push-State
X-Orig-Expires
X-Forwarded-Path
Xc-Version
X-HostName
X-LiteSpeed-Cache-Control
CDN
X-CACHE-AGE
Odigeo-Trace-Id
X-Gamma-Serve
X-PHP-Backend
MIME-Version
Cmstype
True-Client-Ip
X-Varnish-Beresp-TTL
Cmsid
X-Tt-Logid
X-Dynatrace-Js-Agent
X-NodeID
X-Vgn-Hpd-Reason
X-Custom-Header
X-Vmg-Version
CPC-Age
CPC-Cache
User-Agent
Tcn
X-Info
Load-Balancing
X-B3-Spanid
X-AIR-PT
X-Webkit-Csp-Report-Only
X-Geo
X-Pad
X-Depends
X-Vc
X-Fastly-Country-Code
X-Dispatch
X-HOST
Srv
X-Cdn-Diag
Request-ID
X-DefHash
X-Varnish-CookieHashed-On
X-DefElseHash
X-FPC
Ohc-File-Size
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Cdn-Forward
X-Datacenter
X-CSRF-TOKEN
Cl-Cache
X-WA
Hostname
X-M-Reqid
X-NC
X-M-Log
X-VC-TTL
X-Variation
X-APP-VERSION
Server-Id
GeoIP-Country-Code
CacheControlHeader
Ohc-Cache-HIT
X-TimeS
X-LAGOON
X-Cdn-Cache-Status
X-Lb-Nocache
X-Cache-FS-Status
Geoip-Latitude
X-Api-Version
X-Oracle-DMS-ECID
X-ServedByHost
X-APP
Epwk-X-Cache
VNS-Age
VNS-Cache
Cloudfront-Viewer-Country
X-Cache-Ttl
X-Litespeed-Tag
FSS-Cache
X-Via-PopH
CountryCode
Server-Info
PICS-Label
X-Ha-Backend
X-Via-PopN
X-Via-PopV
X-Fastly-Backend-Reqs
X-Litespeed-Cache-Control
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-VCL-Version
X-MSEdge-Flight
X-MSEdge-Features
X-Lb-Id
X-Proxy-Cache-La3
X-FL-QIT-DEBUG
Xkey-La3
Srvid
BehaviorPad-Version
X-Cdn-Request-ID
Xkeylog
ServerHost
X-Th-Server
X-IN-APIGATEWAYSSL
X-Akamai-Pragma-Client-IP
X-Check-Cacheable
X-Dispatcher-Number
X-IN-APIGATEWAY
OriginIP
Ngx
X-MiniProfiler-Ids
X-RequestId
X-Web-Server
X-Serial
X-Acquia-Application-UUID
Memcached
X-Acquia-Purge-Tags
X-Acquia-Site
X-Snapshot-Date
X-Acquia-Application-Trace
Memory
Time
X-Sorting-Hat-Podid
X-Shopid
X-Sorting-Hat-Shopid
X-Shardid
X-Cache-Version
Serverhost
X-RAMCache
X-Ramcache
Warning
X-Service-Response-Time
X-Dw-Trace-Id
X-Mg-Cache
Sm-Log-Id
Akamai-Cache-Status
X-Requestid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Udemy-Cache-App-Namespace
X-Sucuri-Id