Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
P3p
X-Drupal-Cache
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
X-Check
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
X-Request-ID
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
X-UA-Device
Cf-Edge-Cache
X-Backend
Keep-Alive
Request-Context
X-Robots-Tag
Allow
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
EagleId
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
X-Rq
X-Vhost
X-Dispatcher
X-Amz-Version-Id
X-Server-Powered-By
X-Dns-Prefetch-Control
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-LiteSpeed-Cache
X-Device
Permissions-Policy
Cf-Railgun
X-WebKit-CSP
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Backend-Server
X-CST
X-Aws-Lambda-Call-Status
X-Cache-Lookup
X-Host
X-Server-Id
X-Readtime
X-Akam-SW-Version
X-Response-Time
Surrogate-Control
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Litespeed-Cache
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Country
X-Trace
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Url
Accept-Ch-Lifetime
X-Rack-Cache
Rating
Cache-Tag
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
X-Origin-Cache-Key
X-Edge
X-Mcache
Cross-Origin-Opener-Policy
X-PC
X-TtlSet
X-Vname
Nginx-Cache
X-Midtier
X-MS-InvokeApp
X-NWS-LOG-UUID
X-Mod-Pagespeed
X-Upstream
X-ECACHE
X-Powered-By-Plesk
X-Times
X-Server-Name
Edge-Control
X-Browser-Type
X-ESI
X-Cnection
X-Exp-Id
X-Kinja-Server
X-Element-Page-Cache
X-Cdn-Fetch
X-D2id
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-Kinja-Build
X-Kinja-Revision
Verso
X-Ser
AR-PoweredBy
AR-SID
AR-Request-ID
AR-ATIME
X-Ruxit-Js-Agent
X-Ac
SPRequestDuration
SPIisLatency
X-RateLimit-Remaining
X-SharePointHealthScore
SPRequestGuid
X-GitHub-Request-Id
X-B3-TraceId
X-Abt-Application-Version
X-NF-Request-ID
X-Navigation-Version
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-Ttl
AR-CACHE
X-Mg-S
Display
X-Sol
Pagespeed
X-Middleton-Display
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Edge-Cache-Tag
S
Fastly-Restarts
X-Cache-Key
X-VARITI-CCR
X-Client-IP
X-Instrumentation
X-Amzn-Trace-Id
X-Erf-Bev-Bev-Is-Generated
X-Cache-TTL
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Amz-Rid
X-Server-Lifecycle-Phase
RTSS
X-Daa-Tunnel
Cache-Status
X-Powered-CMS
X-Kinsta-Cache
X-Edge-Location-Klb
X-Version
X-Server-ID
Access-Control-Request-Method
X-Goog-Hash
X-Middleton-Response
Response
X-Recruiting
X-Content-Digest
X-Varnish-TTL
X-ARC
X-Forwarded-For
X-T
X-FastCGI-Cache
X-TraceId
Arr-Disable-Session-Affinity
X-MSEdge-Ref
Cross-Origin-Resource-Policy
Content-MD5
MS-Author-Via
MicrosoftSharePointTeamServices
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Front-End-Https
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
TP-Cache
X-Shield-Request-Id
X-Accel-Expires
X-FTR-Backend
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Hits
X-RateLimit-Limit
X-Cached
X-Forwarded-Proto
X-HS-Combine-CSS
X-HS-Cache-Config
X-FTR-Expires
X-Webkit-Csp
X-HS-Hub-Id
X-HS-Content-Id
Public-Key-Pins
X-Id
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
Server-Node
X-Frontend
Realpath
Payment
X-Protected-By
X-DIS-Request-ID
X-LLID
X-Content-Security-Policy-Report-Only
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Distributor
X-ORACLE-DMS-RID
X-Fastly-Request-ID
X-GUploader-UploadID
TP-L2-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Hostname
X-LB-Cache
Cache-Tags
X-Correlation-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Debug-Info
Count-Hit
Fastcgi-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Page-Id
X-Envoy-Decorator-Operation
Referer-Policy
X-Geo-Country
Host
X-Az
X-Activity-Id
X-B3-TraceId-Primal
X-AppVersion
Mrf-Cache-Status
MRF-Tech
X-Origin-Server
X-Varnish-Backend
X-Www-Served-By
Origin-Trial
X-Cluster-Name
X-NGENIX-Cache
X-Varnish-Server
Accept-Charset
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-App-Server
X-ORACLE-DMS-ECID
X-Fastcgi-Cache
X-PressLabs-Stats
X-Ezoic-Cdn
X-F-Cache
X-XRDS-LOCATION
Retry-After
X-Px
X-Load-Cache
X-FB-Debug
X-Ratelimit-Limit
TCN
X-Goog-Metageneration
X-RateLimit-Reset
X-Upgrade-Enabled
X-Seen-By
Access-Control-Allow-Method
Server-Name
X-Amz-Meta-S3cmd-Attrs
Cleartype
X-Git-Hash
X-Varnish-Ttl
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-CSRF-Token
X-Webkit-CSP
X-Request-Guid
X-Grace
Section-Io-Cache
X-Revision
X-Cache-Control
Healthy
X-Trace-Id
X-TT
X-Azure-Ref
X-B3-Sampled
X-Oracle-Dms-Ecid
X-B
X-Contextid
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
Paypal-Debug-Id
Charset
X-Type
X-Whom
X-Fb-Rlafr
DC
X-Content-Options
X-Air-Pt
X-Wix-Request-Id
X-Proxy
X-Mobile
X-Signature
X-B-Cache
X-App-Environment
X-N
Accept-Ch
X-Node-Name
X-Oracle-Dms-Rid
X-Newrelic-App-Data
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Amz-Replication-Status
X-Magnolia-Registration
Filterid
Frame-Options
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Logged-In
X-EdgeConnect-Cache-Status
X-Origin-Cache
X-TTL
Viewport
Backend
Content-Disposition
NGB
X-Time
X-Debug
VIX-Pulpo-Node
X-Original-Request-Id
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Unique-Id
X-Is-Bot
X-ProcessESI
X-Debug-IsConnected
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Rendered-As
X-Debug-IsPreview
X-Tumblr-User
X-RemovedCookies
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Datadog-Sampled
X-Adobe-Loc
Liferay-Portal
X-Adobe-Content
Ms-Operation-Id
MS-CV
SD-X-WS
X-FW-Dynamic
X-RTag
X-Varnish-Grace
X-Servername
X-FW-Type
X-FW-Version
X-Ratelimit-Remaining
X-G
X-FW-Server
X-FW-Static
X-FW-Hash
X-FW-Serve
Upgrade-Insecure-Requests
X-Backend-Name
X-Cache-Grace
X-Hl-Ver
Akamai-GRN
X-IPS-LoggedIn
X-Instance
X-UUID
X-Cacheable-TTL
X-NYM-Debug-Backend
Fastly-SIE
X-Amzn-Remapped-Content-Length
Fastly-SWR
X-Device-Type
X-Via-JSL
ServerID
From-Origin
X-Region
X-VC-Cache
X-User-Agent
X-Cache-Hit
X-L-Path
X-Proxy-Cache-Info
X-Environment-Context
X-Rule
Country
X-Status
X-Rid
Version
Refresh
X-Cache-Age
X-Template
X-B3-SpanId
X-Language
CDN-RequestId
X-Source
X-INCAP-ABP
X-Fastly-Request-Id
Countrycode
GEO-INFO
Url
X-Storage
SRV
X-HTML-Minification-Powered-By
X-NODE
X-WP-CF-Super-Cache-Active
X-Cache-Status-Check
Alternate-Protocol
X-Origin-TTL
X-Origin-CC
X-Providence-Cookie
X-Route-Name
X-Flags
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-App-Version
WPO-Cache-Status
Amp-Access-Control-Allow-Source-Origin
WPO-Cache-Message
X-Jobs
X-B3-Traceid
OT-Force-Account-Verify
X-Real-IP
X-CDN-Forward
X-Akamai-Request-ID2
X-ServerID
X-Content-Powered-By
Surrogate-Key
X-Cache-Time
Access-Control-Request-Headers
Protected
X-XRDS-Location
X-Mode
AMP-Access-Control-Allow-Source-Origin
X-Rocket-Nginx-Serving-Static
X-Accel-Version
X-Hosted-By
X-Nginx-Cache
X-Handled-By
X-Sucuri-Cache
X-VC
X-Akamai-Edgescape
Webserver
X-Endurance-Cache-Level
X-Web-Node
Filters
Meta-Geo
X-Xfnlog-Site
X-UPSTREAM-Address
X-Rn-Rsrv
X-Sucuri-ID
Xet-Cookie
X-Platform-Processor
X-Upstream-Ht
X-Upstream-Ct
X-Platform-Cluster
X-TT-LOGID
X-Rewrite-Enabled
X-Platform-Router
X-Timing-Wait
X-Edge-Location
X-Drupal-Cache-Tags
X-PHP-Host
X-GeoCode
X-GeoCountry
Section-Io-Id
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Labrador-Cache-Channel
X-Detected-As
Selected-Fe
X-Cache-Debug
Atl-Traceid
X-AWS-Id
X-Adobe-Source
X-Cache-Rule
X-Cache-Operation
X-Proxy-Build
X-Framework
ServedBy
Cross-Origin-Embedder-Policy
X-Origin
X-Served-From
X-SaId
X-JoinUs
X-Webstats-RespID
X-LJ-Flow-ID
X-Worker
X-VWS-Id
X-Logging-Id
X-SayCDN-TTL
X-Say-TTL
X-RM-Cache-TTL
X-Proxied
X-Restarts
X-VCT
X-Cms-Context
Webcakes-Region
X-Cluster
Webcakes-App-Name
Property-Id
TWC-Connection-Speed
Node
X-Vcache
Mn-Server-Ip
Front
X-Say-Cacheable
TWC-Device-Class
Web-Mar-Node
X-Director
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-App-Version
X-Zipkin-Id
X-Origin-Hint
X-Extlb
X-Skip-Cache
X-Routing-Service
X-Redis-Cache
X-Drupal-Cache-Contexts
X-Varnish-Cache-Hits
X-No-Session
X-Soup
X-Tncms
X-Is-Supported-Browser
X-Vercel-Cache
X-Is-Mobile
X-ProxyCache-Key
X-ProxyCache-Status
X-Varnish-Age
X-Loop
X-S
X-Site-Version
X-Tb
X-Locale
X-IPLB-Instance
X-Fetched-On
X-Forwarded-Host
X-Is-Tablet
X-Origin-Date
Xserver
X-Lambda-Id
X-Tcp-Rtt
X-BYPASS-REASON
X-Vercel-Id
X-IPLB-Request-ID
X-AB
X-RCS-CacheZone
X-Geo-Region
X-Browser-Name
X-Is-Desktop
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-RequestCountryCode
CDN-CachedAt
Apigw-Requestid
CDN-Cache
CDN-Uid
CDN-PullZone
Azure-SiteName
Azure-SlotName
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Alternate-Cache-Key
Azure-RegionName
X-Cache-Host
X-Varnish-Beresp-Grace
X-Container-Uri
Azure-InstanceId
X-Reqid
Azure-Version
X-Git-Commit
X-R9-Blue-Green-Version
X-Frame-Option
X-Generation-Time
X-Format
X-Httpd
X-Ms-Request-Id
X-Ms-Version
CF-IPCountry
Accept-Language
X-Provided-By
X-Cache-Server
X-Cdn-Origin
X-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-ShopId
Fastcgi-Useragent
DB-Nickname
X-Page-View
WP-Super-Cache
X-Server-W
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Uri
X-MP-GENERATED-AT
X-Vcl-Version
X-Use-Mantle
Cross-Origin-Embedder-Policy-Report-Only
X-Azure-Ref-OriginShield
X-SRV
Source
X-Generated-By
Cross-Origin-Window-Policy
X-RID
X-Shield-Cache-Expires
X-Scope-Id
Thinkindot-CacheControl-Type
TDXMobile
Thinkindot-CacheControl
Thinkindot-Control
X-CMSURLCustom
X-Thinkindot-L3
Cache-Tv-Group
Cache
X-FB-TRIP-ID
X-Buckets
X-Pass-Why
X-Kinja-CCPA
Content-Secure-Policy
X-DataDome
X-LSADC-Cache
Sid
X-Http-Reason
X-UA
Onion-Location
X-Urbn-Site-Id
X-Optimistic-Header
Locale
X-Urbn-Context-Path
Priority
X-Content-Age
X-DynaTrace
X-WP-CF-Super-Cache-Cookies-Bypass
X-Lagoon
X-GEO
HostName
X-Xrds-Location
X-TA-CDN-Provider
X-Proxy-Cache-Status
X-Request-URI
LB
User-Cache-Control
X-Cluster-Node
X-Sql-Count
X-Dc
X-Sql-Duration-Ms
DSUID
Expiry
Magicmarker
X-Conf
X-Ec-Fail
X-Connection-Hash
MD5-Digest
Lang
DCR-Processing-Time-Ms
Gannett-Cam-Experience-Id
A
Yak-Timeinfo
X-Destination
X-Zen-Fury
X-ND-Cache
X-Op-Id-All
X-Developer
Fastly-Drupal-HTML
X-Dispatcher-Server
Candidate-Md5Url
Cdnsip
C-Via
X-Ec-GeoHdr
X-D
Locid
DCR-Decision-By
Origin
X-A
X-A-Ccd
X-A-Dam
Vix-Hermes-Req-Id
T-Server
Sslversion
Surrogated-Key
X-A-Dcw
X-A-Dgt
X-Application
X-B-Cookie
X-AK-Request-ID
X-Aed
X-A-Wwc
X-BCube-Filmed-By
X-Bl-Debug
Sever-Int
Origin-Agent-Cluster
Redirect-Candidate
X-Cache-NE
X-Bc-Bl
Ngx.Var.Host
Meta-Geo-Continent
Ngx-Var-Key
Release
Rendered-Blocks
Server-Hostname
X-External-Request-Id
Server-Host
Server-Ext
Req-ID
X-Cache-Bucket
X-Epic-Correlation-Id
Cdncip
X-Varnish-Beresp-Ttl
X-ScT
X-UA-Device-Type
X-PDP-UNCACHING-HASH
X-SRCache-Key
X-Viewer-Country
X-SB
X-TIM-N
X-Rojux
X-S-Cookie
X-Request-Start
X-Platform
X-Varnish-Hostname
X-Vtex-Remote-Cache
X-Vdms-Path
X-Vdms-Version
X-Origin-Response-Time
X-Newrelic-Synthetics
X-Ua-Device
X-Cache-Action
X-Scheme
X-Amz-Meta-Cb-Modifiedtime
X-Amz-Storage-Class
Environment
X-GeoIP-Region-Code
Tube-Got-Results
X-GeoIP-Country-Code
X-Fastly-Cache
Fastly-SSL
Tube-Got-Eval
Tube-Return
Content-Style-Type
Content-Script-Type
True-Client-Country-4JS
X-Auto-Login
X-Forwarded-Site
Tube-Get-Contents
X-Gdpr
X-Gzip
X-Thanos
X-Ad-Load-Variation
Wxu-Next-Region
Platform
Pramga
X-SVT-ORM-RULES
Wxu-Next-Hostname
NM-Fastcgi-Cache
X-Origin-Expires
On-Server
Wxu-Next-Commit
X-WA-Info
X-GeoIP
X-GeoIP-City
Is-Eu
Host-ID
V-Age
Producers
X-SD-PageType
X-Gen-Mode
X-SVT-ORM-VERSION
X-Generated-On
X-Hnp-Log
X-Pubstack
X-Clientip
X-Contensis-Viewer-Groups
X-Ec-Custom-Error
XM
X-Device-Os
X-Moov-Xdn-Version
X-Level-Front-Cache
X-Loc
Cluster
X-Moov-T
X-Core-Value
X-DPWN-IS-SECURE
X-Nyt-Route
X-Debug-Cache-Store
X-PAYTM-SRV-ID
X-Origin-Time
X-Node-Id
X-Debug-Cache-Fetch
X-NCache
X-Varnishpool
X-Nginx-Cache-Key
X-NMSegId
X-Cache-TTL-Remaining
X-Esi-Check
X-Bip
X-Varnish-Authentication
CDCHOST
X-Cache-Aspx
X-Human
X-Block-Status
X-Cache-Date
X-Cache-Id
X-Req
X-Instance-Name
Click-Count-Action-Start
X-B3-Trace-ID
Click-Count-Error
Adler-Geo
X-Datadome
X-Service
X-Fmm-Version
X-V-Cache
Uber-Trace-Id
X-ApacheServer
X-FC-Vary-Parameters
X-From
X-BBC-Edge-Cache-Status
X-Backend-Instance
X-Cache-Backend
X-Varnish-Director
X-Cdn-Srv
X-Cache-Info
X-TH-Server
X-Acquia-Purge-Cdn-Unconfigured
X-Access
X-Aicache-OS
X-VG-WebCache
X-Varnish-Beresp-Status
X-Var-Ttl
We-Hiring
Web-Mar-Region
X-Cache-Expired-At
X-VG-TLSProxy
X-VarnishDD-TTL
X-Sigma
Cache-Provider
Canary
X-Request-Host
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Request-Time
X-Rocket-Build-Number
X-GoCache-CacheStatus
Fastly-GeoIP-CountryCode
Esi-Enabled
X-HN
X-VServer
Country-Code
Apple-News-Services-Handled
X-Region-Sid
X-Mvc-Supplant-Cachable
X-Pool
X-Policy
X-PERF
X-Org
X-Old-Content-Length
X-Proxied-Request
WZWS-RAY
X-Men
X-RateLimit-Remaining-Second
X-Micro-Cache
X-Mly-Id
X-RateLimit-Limit-Second
Gh-Request-Id
X-HS-Content-Campaign-Id
X-We-Are-Hiring
X-Geo-Header
X-Server-IP
X-Section
X-Sigma-Backend
Req-Svc-Chain
X-Sn-Servicetimems
Ssr
RNT-Time
RNT-Machine
Mail-Subject
PFcat
L
Machine
X-ECache
X-Correlation-ID
Cache-Hits
X-DC
X-App-Name
L5d-Success-Class
X-CGP
X-Fastly-Backend
X-Csrf-Jwt
X-Slack-Shared-Secret-Outcome
HA-Ipaddr
X-Mvc-Supplant-OutputCached
X-Slack-Backend
X-Hash
X-Wikidot-Backend
X-Proto
X-Edge-Server
Cf-Device-Type
X-Test
NGX
Cache-Key
Cdn-Request-Time
Cdn-Host
X-Up
X-Wikidot-Static-Cache
AKAMAI
Proxy-Firewall
W
X-Eu-Site
Ha-Gx-Prefs
X-Zone
X-NWS-UUID-VERIFY
X-Tx-Id
X-Tb-Optimization-Total-Bytes-Saved
X-LB-ID
X-Accel-Expires-Debug
X-NGINX-Cache
X-Branch-Name
Fastly-Backend-Name
X-Ah-Environment
X-CacheTTL
X-API-Version
X-Date
X-Via-SSL
Edge-Copy-Time
X-Via-Edge
X-Mg-Request-UUID
X-Via-CDN
X-COUNTRY
X-Via-Fastly
X-URL
S-Rt
X-VCache
X-Servedbyhost
X-Cloudmap
X-HA-Backend
X-Parent-Response-Time
X-Via-Popv
X-Via-Poph
X-CACHE-GROUP
X-Varnish-Hits
X-Via-Popn
Type
NtCoent-Length
Pics-Label
X-Ratelimit-Reset
Cdn
X-Ig-Origin-Region
X-Location
X-Refresh
X-DynaTrace-JS-Agent
X-Client-Ip
X-VHOST
X-Ua
Datacenter
Fusion-Component-Id
X-CDN-Cache-Status
SID
Fusion-Source
Fusion-Template-Id
GeoIp-Country-Code
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Content-Source
X-Esi
X-Nc
X-LB-NoCache
X-Wa
Powered-By
X-Irp-Debug
X-Akamai-Transformed
X-Owner
X-Jungle-Id
Origin-EX
Origin-CC
X-CUA
X-Core-Mission
Resin-Trace
X-SIPLIST1
Cross-Origin-Opener-Policy-Report-Only
X-Fpc
GeoIP-Latitude
X-User
Server-ID
X-Srv
IsBot
X-Wormhole-Sdk
X-Qloud-Router
X-ZONE
X-TIME
X-Hit
DataCenter
X-CS
X-TX-ID
X-Proxy-CacheRZ
Cdn-Requestid
X-Nf-Request-Id
X-NewRelic-App-Data
CloudFront-Viewer-Country
X-Render-Time
X-B3-Parentspanid
X-Nananana
XkeyRZ
X-Presslabs-Stats
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Segment-20210421
N-Cache
X-Powered-By-VTEX-Cache
Cf-Ipcountry
X-IAuth-Set-Uid
X-Cached-By
Debug
X-CF-Lambda-Fn
Expect-Staple
True-Client-IP
Uri
X-DataCenter
X-CF-Lambda-Version
Mime-Version
X-LiteSpeed-Tag
X-Forwarded-Path
X-Auth-Group-Type
Xc-Version
Edge-Cache
X-Tenant
X-Tt-Logid
X-CACHE-AGE
X-Orig-Expires
X-Cache-Type
X-Shop-Environment
X-TimeS
X-Amz-Meta-Opti
Cmsid
X-Gamma-Serve
Cmstype
Fastly-Drupal-Html
X-Dynatrace-Js-Agent
X-Vc
X-Vmg-Version
X-Info
X-Ig-Push-State
CPC-Cache
CPC-Age
MIME-Version
X-Varnish-Beresp-TTL
User-Agent
True-Client-Ip
CDN
X-LiteSpeed-Cache-Control
Load-Balancing
X-Cs
X-CSRF-TOKEN
X-Fastly-Country-Code
Odigeo-Trace-Id
X-Cdn-Diag
X-Geo
X-B3-Spanid
X-PHP-Backend
X-Vgn-Hpd-Reason
X-Dispatch
X-HOST
X-Custom-Header
Srv
X-NodeID
Hostname
X-HostName
Request-ID
Ohc-File-Size
X-Pad
X-Datacenter
X-Depends
X-Variation
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-DefHash
X-DefElseHash
X-Varnish-CookieINHashed-On
X-FPC
Tcn
X-Varnish-Remaining-TTL
CacheControlHeader
X-Varnish-CookieHashed-On
Cl-Cache
X-LAGOON
X-AIR-PT
X-APP-VERSION
X-WA
Server-Id
X-M-Reqid
X-M-Log
X-NC
X-VC-TTL
Ohc-Cache-HIT
X-Lb-Nocache
GeoIP-Country-Code
X-Api-Version
VNS-Age
VNS-Cache
Geoip-Latitude
X-Cdn-Cache-Status
X-Cache-FS-Status
X-Oracle-DMS-ECID
X-APP
Cloudfront-Viewer-Country
X-ServedByHost
Epwk-X-Cache
X-Cache-Ttl
X-Traceid
PICS-Label
X-Fastly-Backend-Reqs
X-Via-PopV
X-Via-PopN
X-Litespeed-Tag
CountryCode
X-Ha-Backend
X-Via-PopH
X-Litespeed-Cache-Control
X-Srcache-Fetch-Status
X-VCL-Version
X-Srcache-Store-Status
X-Lb-Id
FSS-Cache
Server-Info
X-Proxy-Cache-La3
Xkeylog
X-Serial
X-Check-Cacheable
Xkey-La3
X-Dispatcher-Number
X-MSEdge-Flight
X-Cdn-Request-ID
X-MSEdge-Features
OriginIP
X-IN-APIGATEWAY
X-Th-Server
X-MiniProfiler-Ids
X-Akamai-Pragma-Client-IP
X-RequestId
BehaviorPad-Version
Ngx
X-IN-APIGATEWAYSSL
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Site
X-FL-QIT-DEBUG
Time
X-Acquia-Purge-Tags
Srvid
Memory
X-Web-Server
Memcached
X-Sorting-Hat-Podid
X-Shopid
X-Sorting-Hat-Shopid
X-Shardid
X-Cache-Version
ServerHost
X-RAMCache
X-Requestid
X-Ramcache
Serverhost
X-Udemy-Cache-App-Namespace
X-Service-Response-Time
Akamai-Cache-Status
X-Dw-Trace-Id
X-Mg-Cache
Sm-Log-Id
X-Snapshot-Date
X-Sucuri-Id
Warning
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Mid