Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Served-By
X-UA-Compatible
P3P
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
P3p
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
X-Ua-Compatible
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Allow
X-Backend
Cf-Edge-Cache
Request-Context
X-Robots-Tag
Keep-Alive
X-Cache-Group
X-Server
X-UA-Device
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-WebKit-CSP
X-CST
X-Backend-Server
Permissions-Policy
X-OneAgent-JS-Injection
X-Server-Id
X-Readtime
X-Response-Time
X-Akam-SW-Version
X-Host
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
Accept-Ch-Lifetime
X-Litespeed-Cache
X-Application-Context
X-Oneagent-Js-Injection
X-Cache-Lookup
X-Country-Code
X-Trace
Content-Location
X-Url
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Content-Type
X-Clacks-Overhead
X-Country
X-Edge
X-ECACHE
X-Origin-Cache-Key
X-Mcache
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-Mod-Pagespeed
Cross-Origin-Opener-Policy
X-Midtier
Cache-Tag
X-FTR-Request-ID
Accept-Ch
Nginx-Cache
X-MS-InvokeApp
X-Upstream
X-PC
X-TtlSet
X-Vname
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-Ruxit-Js-Agent
X-Browser-Type
X-Server-Name
X-D2id
X-Element-Page-Cache
Verso
X-Exp-Id
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Variant
X-Times
X-GoogleNews-Bot
X-Cnection
X-Ac
X-B3-TraceId
SPIisLatency
SPRequestDuration
AR-ATIME
AR-SID
AR-Request-ID
AR-PoweredBy
X-Abt-Application-Version
X-Navigation-Version
X-Vcap-Request-Id
SPRequestGuid
X-SharePointHealthScore
X-NF-Request-ID
X-Dw-Request-Base-Id
X-GitHub-Request-Id
X-Ser
X-RateLimit-Remaining
AR-CACHE
X-VARITI-CCR
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Mg-S
X-NWS-LOG-UUID
S
X-Cache-Key
X-Sol
Display
X-Middleton-Display
Pagespeed
RTSS
Edge-Cache-Tag
Fastly-Restarts
X-Amz-Rid
X-Amzn-Trace-Id
X-Client-IP
X-Ttl
X-Cache-TTL
X-Powered-CMS
X-Goog-Hash
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
Origin-Trial
Cache-Status
X-Edge-Location-Klb
X-Kinsta-Cache
X-Varnish-TTL
X-Version
Access-Control-Request-Method
X-Content-Security-Policy-Report-Only
X-Server-ID
X-Recruiting
X-ARC
X-TraceId
X-Content-Digest
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Arr-Disable-Session-Affinity
X-Middleton-Response
Response
X-Webkit-Csp
X-T
X-Forwarded-For
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
X-Ua-Device
X-Accel-Expires
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
X-Id
Public-Key-Pins
X-RateLimit-Limit
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
MS-Author-Via
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Server-Node
X-Ua-Browser
Cross-Origin-Resource-Policy
X-HS-Combine-CSS
Payment
X-Request-Received
Front-End-Https
X-Request-Processing-Time
X-Daa-Tunnel
X-Frontend
X-DIS-Request-ID
X-FastCGI-Cache
X-Forwarded-Proto
X-LLID
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-GUploader-UploadID
TP-L2-Cache
Realpath
X-Protected-By
X-LB-Cache
Cache-Tags
X-Fastcgi-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-Distributor
X-Microsite
X-Request-Handler-Origin-Region
X-WebKit-CSP-Report-Only
Count-Hit
X-Page-Id
X-AppVersion
X-Az
X-Activity-Id
X-Cluster-Name
MRF-Tech
Mrf-Cache-Status
X-Hostname
X-F-Cache
X-TTL
X-B3-TraceId-Primal
X-Varnish-Backend
Referer-Policy
X-Www-Served-By
X-Correlation-Id
X-Debug-Info
X-Geo-Country
X-ORACLE-DMS-RID
Accept-Charset
X-NGENIX-Cache
Fastcgi-Cache
X-App-Server
X-Kong-Proxy-Latency
X-PressLabs-Stats
X-Kong-Upstream-Latency
X-Kinja-CCPA
Host
X-Envoy-Decorator-Operation
X-Varnish-Server
X-Goog-Metageneration
X-FB-Debug
Access-Control-Allow-Method
X-Oracle-Dms-Ecid
X-Git-Hash
X-RateLimit-Reset
Retry-After
X-Rid
X-ORACLE-DMS-ECID
Server-Name
X-Content-Options
X-Load-Cache
X-Upgrade-Enabled
X-Oracle-Dms-Rid
X-Px
X-Tt-Trace-Tag
X-XRDS-LOCATION
X-Ratelimit-Limit
X-Tt-Trace-Host
X-Is-Crawler
X-Request-Guid
X-Revision
X-Route-Name
X-Providence-Cookie
TCN
X-Aspnet-Duration-Ms
DC
X-Contextid
X-Flags
Charset
X-App-Environment
X-TEC-API-VERSION
X-Trace-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ezoic-Cdn
X-CSRF-Token
X-Cache-Control
X-Type
X-Datadog-Parent-Id
Paypal-Debug-Id
X-Seen-By
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Grace
X-Origin-Cache
X-B3-Sampled
Cleartype
X-Signature
X-Amz-Meta-S3cmd-Attrs
X-B-Cache
Section-Io-Cache
X-Fastly-Request-Id
X-Mobile
X-B
X-TT
X-Fb-Rlafr
Healthy
X-Whom
X-Wix-Request-Id
X-Amz-Replication-Status
Frame-Options
X-ASPNET-VERSION
X-Fastly-Request-ID
X-Magnolia-Registration
X-Node-Name
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Logged-In
X-Language
Filterid
X-EdgeConnect-Cache-Status
X-Varnish-Ttl
X-Azure-Ref
X-Proxy
X-Newrelic-App-Data
X-N
X-Ratelimit-Remaining
X-Air-Pt
Content-Disposition
X-App-Version
Backend
Akamai-GRN
Upgrade-Insecure-Requests
X-Template
X-Original-Request-Id
Refresh
NGB
X-Proxy-Cache-Info
X-Response-Served-From
X-Tumblr-Pixel
X-Rendered-As
X-Tumblr-Pixel-0
X-Tumblr-User
X-ProcessESI
X-Unique-Id
X-RemovedCookies
X-Tumblr-Pixel-1
X-Is-Bot
X-Yottaa-Metrics
SD-X-WS
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Yottaa-Optimizations
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Viewport
Ms-Operation-Id
X-Datadog-Sampled
X-RTag
X-Instance
X-Amzn-Remapped-Content-Length
MS-CV
X-Page-View
X-Servername
X-Varnish-Grace
X-Debug-IsPreview
X-IPS-LoggedIn
X-FW-Server
Liferay-Portal
X-Debug-IsConnected
X-FW-Dynamic
X-FW-Hash
X-FW-Version
X-FW-Type
X-FW-Serve
X-UUID
X-Debug
X-FW-Static
X-Cache-Grace
X-User-Agent
X-Adobe-Content
X-Cacheable-TTL
Fastly-SWR
X-Region
X-Adobe-Loc
Fastly-SIE
From-Origin
Url
X-Device-Type
X-G
X-Rule
X-NYM-Debug-Backend
X-L-Path
Country
X-Jobs
X-Cache-Hit
X-Environment-Context
X-Hl-Ver
X-Backend-Name
X-B3-SpanId
X-Status
Amp-Access-Control-Allow-Source-Origin
ServerID
X-Time
Surrogate-Key
X-Hosted-By
X-Air-Trace-Id
X-Origin-TTL
X-Origin-CC
X-Hcs-Proxy-Type
X-Air-Hostname
X-CCDN-CacheTTL
X-Air-Source
X-CCDN-Origin-Time
X-Webkit-CSP
Alternate-Protocol
X-VC-Cache
X-Via-JSL
X-Cache-Age
Countrycode
X-Akamai-Request-ID2
X-INCAP-ABP
X-Content-Powered-By
X-Cache-Status-Check
Version
X-Tec-Api-Origin
X-HTML-Minification-Powered-By
X-Tec-Api-Root
X-Tec-Api-Version
WPO-Cache-Status
WPO-Cache-Message
Protected
SRV
X-XRDS-Location
X-NODE
X-Http-Reason
GEO-INFO
X-Nginx-Cache
X-Rocket-Nginx-Serving-Static
X-Akamai-Edgescape
CDN-RequestId
CF-IPCountry
X-B3-Traceid
X-CDN-Forward
X-Framework
X-Storage
X-Source
X-WP-CF-Super-Cache-Active
X-Accel-Version
X-Edge-Location
X-Cache-Rule
Access-Control-Request-Headers
Front
X-Real-IP
X-Mode
OT-Force-Account-Verify
X-Httpd
X-Xfnlog-Site
X-UPSTREAM-Address
Webserver
X-Rn-Rsrv
X-Rewrite-Enabled
X-Upstream-Ht
X-Upstream-Ct
Filters
X-Cache-Operation
Meta-Geo
Accept-Language
X-Endurance-Cache-Level
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Proxy-Build
X-Director
Selected-Fe
X-Served-From
X-SaId
X-Timing-Wait
X-JoinUs
X-Soup
X-Cache-Debug
X-SayCDN-TTL
X-Origin
ServedBy
X-Use-Mantle
X-Use-Magma
X-Logging-Id
X-Redis-Cache
X-Varnish-Cache-Hits
X-Handled-By
X-Worker
X-Detected-As
X-Say-Cacheable
X-Say-TTL
Webcakes-App-Name
TWC-Locale-Group
TWC-Privacy
X-RM-Cache-TTL
Web-Mar-Node
Webcakes-Region
X-Adobe-Source
TWC-GeoIP-LatLong
Webcakes-App-Version
X-Format
X-Lambda-Id
X-Labrador-Cache-Channel
TWC-Connection-Speed
TWC-Device-Class
X-PHP-Host
Property-Id
X-Restarts
DB-Nickname
X-Origin-Hint
X-Loop
X-GeoCountry
X-GeoCode
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-ProxyCache-Status
TWC-GeoIP-Country
X-Cms-Context
X-ProxyCache-Key
X-Cache-Time
Azure-Version
X-BYPASS-REASON
X-Varnish-Age
X-VC
X-VCT
Xserver
X-Tncms
X-Vcache
X-Sql-Count
X-Sql-Duration-Ms
X-Server-W
X-No-Session
X-RCS-CacheZone
X-VWS-Id
X-Git-Commit
X-Vercel-Id
Mn-Server-Ip
X-AWS-Id
X-Fetched-On
X-Container-Uri
X-Cache-Server
X-Generation-Time
X-DynaTrace
X-Vercel-Cache
X-ServerID
Apigw-Requestid
X-Skip-Cache
Xet-Cookie
X-LJ-Flow-ID
X-IPLB-Instance
X-Tb
X-Varnish-Beresp-Grace
X-IPLB-Request-ID
Node
Section-Io-Id
X-Reqid
X-Cache-Host
X-Provided-By
X-Cluster
X-Web-Node
X-Frame-Option
X-Proxied
X-Is-Supported-Browser
X-Geo-Region
X-Is-Tablet
X-Is-Desktop
X-Extlb
X-Forwarded-Host
X-Is-Mobile
X-Browser-Name
X-AB
X-Zipkin-Id
X-Routing-Service
X-Locale
X-Site-Version
X-Ms-Request-Id
X-Ms-Version
X-Tcp-Rtt
X-S
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-R9-Blue-Green-Version
Cross-Origin-Embedder-Policy
X-Uri
X-Webstats-RespID
Cache-Tv-Group
X-Drupal-Cache-Tags
Priority
X-Drupal-Cache-Contexts
Source
Fastcgi-Useragent
X-MP-GENERATED-AT
X-FB-TRIP-ID
X-Origin-Date
WP-Super-Cache
Content-Secure-Policy
X-COUNTRY
CDN-Uid
AMP-Access-Control-Allow-Source-Origin
CDN-Cache
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-CachedAt
CDN-RequestPullSuccess
CDN-PullZone
X-Vcl-Version
X-TT-LOGID
X-Generated-By
Onion-Location
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Alternate-Cache-Key
X-Urbn-Site-Id
X-Sucuri-Cache
X-Urbn-Context-Path
Locale
X-Content-Age
X-ShardId
X-Sorting-Hat-ShopId
S-Rt
X-Sorting-Hat-PodId
X-ShopId
X-Xrds-Location
X-Pass-Why
X-SRV
WZWS-RAY
X-Cdn-Origin
X-Sucuri-ID
X-Newrelic-Synthetics
X-Cluster-Node
X-Buckets
X-Varnish-Beresp-Ttl
X-Ua
Cross-Origin-Embedder-Policy-Report-Only
Sid
X-DataDome
X-Cache-Action
X-Proxy-Cache-Status
X-Thinkindot-L3
X-CMSURLCustom
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Scope-Id
X-Shield-Cache-Expires
Thinkindot-Control
X-Cache-Expired-At
Cross-Origin-Window-Policy
Cache
X-LSADC-Cache
Atl-Traceid
X-GEO
Fastly-Drupal-HTML
X-Via-Edge
Edge-Copy-Time
X-Via-CDN
X-Request-URI
X-Via-SSL
X-Cache-NE
X-Conf
X-A-Ccd
X-Cache-Bucket
X-Mg-Request-UUID
X-Bl-Debug
X-A
T-Server
X-Destination
X-Developer
Type
DCR-Decision-By
X-D
Candidate-Md5Url
Sslversion
X-B-Cookie
X-Bc-Bl
X-Application
X-Aed
Surrogated-Key
X-A-Dgt
X-Ec-Fail
X-A-Dcw
X-A-Dam
X-BCube-Filmed-By
CDCHOST
X-Vtex-Remote-Cache
X-A-Wwc
X-Ec-Custom-Error
Meta-Geo-Continent
X-PAYTM-SRV-ID
X-Optimistic-Header
X-Scheme
X-Vdms-Path
X-ScT
X-S-Cookie
Origin-Agent-Cluster
X-TIM-N
Ngx.Var.Host
Gannett-Cam-Experience-Id
X-Rojux
Origin
X-Vdms-Version
X-WP-CF-Super-Cache-Cookies-Bypass
X-External-Request-Id
Lang
X-SRCache-Key
X-Epic-Correlation-Id
X-Ec-GeoHdr
Ngx-Var-Key
Rendered-Blocks
DCR-Processing-Time-Ms
X-Viewer-Country
Redirect-Candidate
MD5-Digest
X-Aspnetmvc-Version
Host-ID
Magicmarker
Fastly-GeoIP-CountryCode
Req-ID
Release
Server-Ext
Server-Hostname
Server-Host
Sever-Int
DSUID
Fastly-SSL
Pramga
L
Environment
Ssr
X-Debug-Cache-Fetch
X-Rocket-Build-Number
X-SB
X-SD-PageType
X-Section
X-Request-Time
X-Request-Start
X-Pool
X-Proxied-Request
X-Pubstack
X-Sigma
X-Sigma-Backend
X-Varnishpool
X-VG-WebCache
X-VServer
X-We-Are-Hiring
X-Varnish-Hostname
X-Varnish-Director
X-TH-Server
X-Thanos
X-Varnish-Beresp-Status
X-Origin-Time
X-Op-Id-All
X-Debug-Cache-Store
X-Dispatcher-Server
X-Fastly-Cache
X-Forwarded-Site
X-Cache-Info
X-Bip
Vix-Hermes-Req-Id
X-Access
X-Aicache-OS
X-Gdpr
X-Generated-On
X-Loc
X-Node-Id
X-Nyt-Route
X-Level-Front-Cache
X-Instance-Name
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Human
V-Age
X-Clientip
Apple-News-Services-Host
X-Correlation-ID
Apple-News-Services-Parsed-Url
X-VCache
Apple-News-Services-Request-Url
Apple-News-Services-Handled
X-Datadome
HostName
User-Cache-Control
X-Origin-Response-Time
X-TA-CDN-Provider
X-DC
X-TimeS
X-Device-Os
X-Esi-Check
X-Gen-Mode
X-GeoIP-City
X-GeoIP
X-Geo-Header
X-FC-Vary-Parameters
X-Cache-Id
Wxu-Next-Hostname
Wxu-Next-Region
Wxu-Next-Commit
Web-Mar-Region
Uber-Trace-Id
We-Hiring
X-Acquia-Purge-Cdn-Unconfigured
X-ApacheServer
X-Cache-Date
X-Gzip
X-Block-Status
X-BBC-Edge-Cache-Status
X-Auto-Login
X-B3-Trace-ID
X-Core-Value
X-Men
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Server-IP
X-Request-Host
X-Req
X-UA-Device-Type
X-V-Cache
X-Zen-Fury
Cluster
X-WA-Info
X-VG-TLSProxy
X-Var-Ttl
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Mly-Id
X-Mvc-Supplant-Cachable
True-Client-Country-4JS
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Mvc-Supplant-OutputCached
X-NCache
X-Platform
X-Policy
X-PERF
X-Org
X-Nginx-Cache-Key
X-Hnp-Log
X-NMSegId
Canary
C-Via
Gh-Request-Id
Mail-Subject
Machine
On-Server
Cache-Provider
NM-Fastcgi-Cache
Req-Svc-Chain
X-Service
Expiry
X-Connection-Hash
Click-Count-Action-Start
Esi-Enabled
Click-Count-Error
X-App-Name
Is-Eu
X-Cdn-Srv
IsBot
X-Proto
Producers
X-Up
X-Old-Content-Length
X-Ad-Load-Variation
X-SIPLIST1
Platform
Country-Code
X-Test
X-Core-Mission
X-From
X-GoCache-CacheStatus
Tube-Return
Adler-Geo
AKAMAI
W
Tube-Got-Results
Tube-Got-Eval
X-Fmm-Version
X-Fastly-Backend
X-Hash
Tube-Get-Contents
A
X-Branch-Name
X-Moov-T
X-Cache-TTL-Remaining
X-Contensis-Viewer-Groups
X-Cache-Aspx
X-Moov-Xdn-Version
X-Varnish-Authentication
Content-Script-Type
X-DPWN-IS-SECURE
X-Micro-Cache
Content-Style-Type
Cdn-Request-Time
L5d-Success-Class
X-CGP
X-Edge-Server
X-Eu-Site
Pics-Label
HA-Ipaddr
Ha-Gx-Prefs
X-ZONE
X-Csrf-Jwt
X-Slack-Backend
Fastly-Backend-Name
Cdn-Host
Cache-Key
X-Wikidot-Backend
X-Amz-Meta-Cb-Modifiedtime
X-Wikidot-Static-Cache
X-Sn-Servicetimems
Cf-Device-Type
X-CacheTTL
Datacenter
Proxy-Firewall
X-Slack-Shared-Secret-Outcome
X-Parent-Response-Time
Cdncip
X-Region-Sid
Cdnsip
X-AK-Request-ID
X-ND-Cache
Yak-Timeinfo
X-HA-Backend
Locid
X-Via-Popn
X-Via-Poph
X-Dc
X-Via-Popv
LB
RNT-Machine
X-Qloud-Router
X-Owner
RNT-Time
X-Tx-Id
X-Ah-Environment
X-Date
X-Accel-Expires-Debug
X-HN
PFcat
Cdn
X-VarnishDD-TTL
X-Amz-Storage-Class
N-Cache
X-CF-Lambda-Fn
Expect-Staple
X-LB-NoCache
X-CF-Lambda-Version
NGX
X-Azure-Ref-OriginShield
X-Tb-Optimization-Total-Bytes-Saved
X-Orig-Expires
X-Refresh
X-Cache-Type
X-Tenant
SID
X-Servedbyhost
X-Shop-Environment
Xc-Version
X-Backend-Instance
X-LB-ID
X-CACHE-GROUP
X-Forwarded-Path
X-Ratelimit-Reset
X-Gamma-Serve
GeoIp-Country-Code
XM
X-NGINX-Cache
X-Wa
X-Nc
X-CDN-Cache-Status
X-VHOST
X-Client-Ip
X-DynaTrace-JS-Agent
X-Origin-Expires
X-Cache-Backend
X-Varnish-Hits
X-API-Version
X-Tt-Logid
Cmstype
Cmsid
NtCoent-Length
RATING
Server-ID
Cdn-Requestid
CPC-Age
X-Lagoon
X-Srv
X-Vmg-Version
CPC-Cache
CloudFront-Viewer-Country
X-Cdn-Diag
X-Nananana
X-Fpc
X-Akamai-Transformed
X-TIME
X-TX-ID
X-B3-Parentspanid
Resin-Trace
X-Via-Fastly
X-LAGOON
X-Zone
X-UA
X-CACHE-AGE
X-Api-Version
X-NewRelic-App-Data
X-Hit
Uri
Cross-Origin-Opener-Policy-Report-Only
CacheControlHeader
X-Nf-Request-Id
User-Agent
X-Proxy-CacheRZ
X-Variation
XkeyRZ
X-Presslabs-Stats
GeoIP-Latitude
X-URL
MIME-Version
Cache-Hits
X-Fastly-Country-Code
X-Info
X-Location
X-DataCenter
X-Ig-Origin-Region
X-Amz-Meta-Opti
X-Vc
True-Client-IP
Hostname
X-ECache
X-Dynatrace-Js-Agent
Tcn
X-LiteSpeed-Tag
VNS-Age
X-NWS-UUID-VERIFY
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
VNS-Cache
Lb
True-Client-Ip
X-Datacenter
Fusion-Source
X-LiteSpeed-Cache-Control
X-B3-Spanid
DataCenter
X-CSRF-TOKEN
X-HostName
Powered-By
X-RID
Cache-Name
X-CS
X-Geo
X-Cloudmap
X-CUA
X-Jungle-Id
X-Cached-By
Origin-CC
Origin-EX
Mime-Version
Fastly-Drupal-Html
X-Dispatcher-Number
X-User
X-IAuth-Set-Uid
X-HOST
Cf-Ipcountry
Debug
X-Segment-20210421
X-AIR-PT
X-Cdn-Forward
X-Webkit-Csp-Report-Only
Load-Balancing
X-Varnish-Beresp-TTL
X-Render-Time
Cl-Cache
X-Mid
Srv
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-MCACHE
X-Wormhole-Sdk
X-Dispatch
Edge-Cache
Ohc-File-Size
X-Esi
X-Auth-Group-Type
BehaviorPad-Version
X-FPC
GeoIP-Country-Code
CDN
X-Litespeed-Tag
CountryCode
X-Oracle-DMS-ECID
Server-Id
X-Cdn-Cache-Status
Ohc-Cache-HIT
X-Cache-Enabled
X-Ig-Push-State
X-WA
X-NC
X-Lb-Id
YJS-ID
X-ServedByHost
X-Cache-Ttl
X-Cs
My-App
Odigeo-Trace-Id
Location
X-Lb-Nocache
X-Wp-Cf-Super-Cache
X-NodeID
Server-Info
X-Wp-Cf-Super-Cache-Cache-Control
X-Fastly-Backend-Reqs
Ms-Author-Via
Wpo-Cache-Message
X-VCL-Version
X-Litespeed-Cache-Control
Wpo-Cache-Status
X-APP-VERSION
Xkeylog
X-Cdn-Request-ID
Xkey-La3
X-Proxy-Cache-La3
Ngx
CF-Ctrl
X-MSEdge-Flight
CF-Cached-On
X-Custom-Header
X-Snapshot-Date
X-Vgn-Hpd-Reason
X-Internal-Host
X-MSEdge-Features
X-MiniProfiler-Ids
X-Akamai-Pragma-Client-IP
Memcached
X-PHP-Backend
X-App
Section-Io-Origin-Status
Memory
X-Acquia-Application-Trace
X-Acquia-Site
X-Nitro-Cache
X-Depends
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Nitro-Cache-From
Time
Section-Io-Origin-Time-Seconds
X-Nitro-Rev
OriginIP
X-IN-APIGATEWAYSSL
Section-Origin-Responded
X-FL-QIT-DEBUG
X-FL-EDGE
X-Via-PopV
X-Via-PopN
X-Ha-Backend
X-IN-APIGATEWAY
X-Via-PopH
FSS-Cache
Srvid
X-Cache-Version
X-Shopid
X-Sorting-Hat-Shopid
X-Shardid
X-Sorting-Hat-Podid
Akamai-Cache-Status
X-Mg-Cache
X-Pad
X-Fastly-Cache-Hits
X-Lsadc-Cache
X-Sucuri-Id
X-Te-Duration-Ms
X-Te-Count
X-Cache-FS-Status
X-Http-Count
X-Http-Duration-Ms
X-Th-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Serial
X-Service-Response-Time
X-Web-Server
X-Check-Cacheable
Sm-Log-Id
Geoip-Latitude
X-RequestId
X-Udemy-Cache-App-Namespace
X-Dw-Trace-Id