Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-Served-By
X-UA-Compatible
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
P3p
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
X-Ua-Compatible
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Allow
Cf-Edge-Cache
X-Backend
Request-Context
X-UA-Device
Keep-Alive
X-Robots-Tag
X-Cache-Group
X-Server
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-LiteSpeed-Cache
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-WebKit-CSP
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Nginx-Upstream-Cache-Status
X-Litespeed-Cache
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
Accept-Ch-Lifetime
X-Cache-Lookup
X-Application-Context
X-Country-Code
X-Trace
Content-Location
X-Ruxit-JS-Agent
X-Oneagent-Js-Injection
X-Country
Service-Worker-Allowed
X-Url
X-Content-Type
X-Clacks-Overhead
X-Origin-Cache-Key
X-Edge
X-Rack-Cache
X-ECACHE
X-Amz-Server-Side-Encryption
X-Mcache
Cross-Origin-Opener-Policy
X-Midtier
Cache-Tag
X-Mod-Pagespeed
X-FTR-Request-ID
Accept-Ch
Nginx-Cache
X-MS-InvokeApp
X-PC
X-Vname
X-TtlSet
X-Upstream
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-Server-Name
X-Browser-Type
X-D2id
X-Element-Page-Cache
Verso
X-Times
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Cnection
X-Ac
SPRequestDuration
SPIisLatency
AR-Request-ID
AR-SID
AR-PoweredBy
AR-ATIME
X-B3-TraceId
X-Ruxit-Js-Agent
X-Abt-Application-Version
X-Navigation-Version
SPRequestGuid
X-SharePointHealthScore
X-Vcap-Request-Id
X-NF-Request-ID
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-Ser
X-NWS-LOG-UUID
AR-CACHE
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-VARITI-CCR
X-Mg-S
X-RateLimit-Remaining
S
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Client-IP
X-Ttl
X-Cache-Key
RTSS
Edge-Cache-Tag
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Cache-TTL
X-Powered-CMS
X-Goog-Hash
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev
X-Kinsta-Cache
Cache-Status
X-Edge-Location-Klb
X-Version
Access-Control-Request-Method
X-Server-ID
X-Recruiting
Origin-Trial
X-ARC
X-Varnish-TTL
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Content-Security-Policy-Report-Only
X-Content-Digest
X-TraceId
Response
X-Middleton-Response
Arr-Disable-Session-Affinity
X-Forwarded-For
X-Webkit-Csp
X-T
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-MD5
X-Accel-Expires
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
X-Daa-Tunnel
Public-Key-Pins
X-Id
Cross-Origin-Resource-Policy
Front-End-Https
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
MS-Author-Via
X-FTR-Backend
X-FTR-Expires
X-HS-Content-Id
X-Ua-Browser
X-HS-Combine-CSS
X-HS-Cache-Config
Server-Node
X-HS-Hub-Id
X-Request-Received
Payment
X-DIS-Request-ID
X-Request-Processing-Time
X-Frontend
X-Fastcgi-Cache
X-Forwarded-Proto
X-LLID
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-GUploader-UploadID
X-Protected-By
TP-L2-Cache
Realpath
X-FastCGI-Cache
X-LB-Cache
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-ORACLE-DMS-RID
X-Origin-Server
X-Distributor
X-RateLimit-Limit
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
X-Page-Id
X-AppVersion
X-Az
X-Hostname
X-Activity-Id
X-Ratelimit-Limit
X-Cluster-Name
Mrf-Cache-Status
MRF-Tech
X-F-Cache
X-B3-TraceId-Primal
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Backend
Referer-Policy
X-Debug-Info
X-Correlation-Id
X-Www-Served-By
X-Geo-Country
X-NGENIX-Cache
Fastcgi-Cache
Accept-Charset
Host
X-Envoy-Decorator-Operation
X-App-Server
X-Varnish-Server
X-Goog-Metageneration
X-FB-Debug
X-WebKit-CSP-Report-Only
X-Ua-Device
X-ORACLE-DMS-ECID
X-PressLabs-Stats
X-TTL
Access-Control-Allow-Method
X-XRDS-LOCATION
X-Git-Hash
X-Kinja-CCPA
Retry-After
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Fastly-Request-Id
X-Upgrade-Enabled
X-Load-Cache
X-RateLimit-Reset
X-CSRF-Token
X-Content-Options
Server-Name
X-Oracle-Dms-Ecid
X-Rid
X-Ezoic-Cdn
X-Px
X-Tt-Trace-Tag
X-Tt-Trace-Host
TCN
X-Contextid
X-Request-Guid
X-Revision
Charset
X-Seen-By
X-Trace-Id
DC
X-Datadog-Sampling-Priority
X-Cache-Control
X-Varnish-Ttl
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Amz-Meta-S3cmd-Attrs
X-Type
X-Grace
Paypal-Debug-Id
X-App-Environment
Cleartype
X-Signature
X-B-Cache
Section-Io-Cache
X-B3-Sampled
X-TT
X-Ratelimit-Remaining
X-B
X-Fb-Rlafr
Healthy
X-Oracle-Dms-Rid
X-Mobile
X-Whom
X-Wix-Request-Id
X-Origin-Cache
X-ASPNET-VERSION
Frame-Options
X-Node-Name
X-Amz-Replication-Status
X-Is-Crawler
X-Route-Name
X-Providence-Cookie
X-Flags
X-Aspnet-Duration-Ms
X-Newrelic-App-Data
X-EdgeConnect-Cache-Status
X-Magnolia-Registration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Logged-In
X-Language
X-Azure-Ref
Filterid
X-Proxy
X-N
X-Fastly-Request-ID
X-Air-Pt
Content-Disposition
Akamai-GRN
Backend
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Upgrade-Insecure-Requests
X-App-Version
X-Template
X-Response-Served-From
X-Original-Request-Id
NGB
X-Proxy-Cache-Info
Refresh
X-Tumblr-User
X-Yottaa-Metrics
SD-X-WS
X-Yottaa-Optimizations
VIX-Pulpo-Node
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Is-Bot
VIX-Pulpo-Upstream-Status
X-RemovedCookies
X-ProcessESI
X-Rendered-As
X-Tumblr-Pixel-0
X-Unique-Id
Ms-Operation-Id
X-RTag
X-Varnish-Grace
MS-CV
X-Amzn-Remapped-Content-Length
X-Instance
Liferay-Portal
Viewport
X-Servername
X-Datadog-Sampled
X-FW-Dynamic
X-FW-Static
X-Debug-IsConnected
X-FW-Serve
X-Debug-IsPreview
X-Debug
X-FW-Hash
X-FW-Type
X-FW-Server
X-FW-Version
X-IPS-LoggedIn
X-UUID
X-Region
X-Cache-Grace
X-Adobe-Loc
X-Adobe-Content
X-Cacheable-TTL
Fastly-SWR
Fastly-SIE
X-User-Agent
X-G
X-Cache-Age
From-Origin
X-Time
X-Rule
X-NYM-Debug-Backend
X-Device-Type
Url
X-Hl-Ver
X-L-Path
X-Cache-Hit
X-Environment-Context
Country
X-Backend-Name
X-Status
ServerID
X-Jobs
X-Page-View
X-B3-SpanId
Countrycode
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Via-JSL
X-VC-Cache
X-Origin-TTL
Surrogate-Key
X-Origin-CC
X-Air-Trace-Id
X-Air-Hostname
X-INCAP-ABP
X-Air-Source
Amp-Access-Control-Allow-Source-Origin
X-Hosted-By
X-Webkit-CSP
Alternate-Protocol
WPO-Cache-Message
WPO-Cache-Status
X-HTML-Minification-Powered-By
Version
X-Cache-Status-Check
X-Content-Powered-By
X-Akamai-Request-ID2
Protected
X-NODE
GEO-INFO
X-Nginx-Cache
CDN-RequestId
X-Rocket-Nginx-Serving-Static
X-Akamai-Edgescape
X-Source
SRV
X-B3-Traceid
X-Http-Reason
X-WP-CF-Super-Cache-Active
X-Storage
X-Framework
X-Accel-Version
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-VC
Access-Control-Request-Headers
X-Edge-Location
X-CDN-Forward
X-Cache-Rule
CF-IPCountry
X-Real-IP
Front
OT-Force-Account-Verify
X-Mode
Webserver
X-Rn-Rsrv
X-Cache-Operation
X-Xfnlog-Site
X-Upstream-Ct
X-Rewrite-Enabled
X-Upstream-Ht
X-UPSTREAM-Address
Filters
Meta-Geo
X-Httpd
X-Director
Accept-Language
Xet-Cookie
X-Soup
X-SaId
Selected-Fe
X-JoinUs
X-Tumblr-Pixel-2
X-Timing-Wait
X-Tumblr-Pixel-3
X-Proxy-Build
X-Served-From
X-Endurance-Cache-Level
X-Use-Mantle
X-Cache-Debug
X-SayCDN-TTL
X-Redis-Cache
X-Logging-Id
X-Say-Cacheable
X-Say-TTL
ServedBy
X-Varnish-Cache-Hits
X-Handled-By
X-Worker
X-Web-Node
X-Detected-As
X-Cache-Time
X-Origin
X-Restarts
Azure-SlotName
Azure-RegionName
Azure-Version
DB-Nickname
Azure-InstanceId
Azure-SiteName
X-ProxyCache-Key
X-Lambda-Id
Webcakes-Region
X-Loop
X-Varnish-Age
Webcakes-App-Version
X-VCT
X-Tncms
X-GeoCountry
X-Cms-Context
X-BYPASS-REASON
X-RM-Cache-TTL
X-Format
X-GeoCode
Webcakes-App-Name
Xserver
X-PHP-Host
TWC-GeoIP-LatLong
X-Server-W
TWC-GeoIP-Country
X-ProxyCache-Status
TWC-Device-Class
X-Labrador-Cache-Channel
TWC-Locale-Group
X-No-Session
Web-Mar-Node
X-Origin-Hint
TWC-Privacy
X-Adobe-Source
TWC-Connection-Speed
Property-Id
X-ServerID
X-DynaTrace
X-Fetched-On
X-Container-Uri
X-Generation-Time
X-Varnish-Beresp-Grace
X-AWS-Id
Apigw-Requestid
X-Git-Commit
X-Skip-Cache
X-IPLB-Instance
X-Vercel-Cache
X-RCS-CacheZone
X-Tb
X-Vercel-Id
X-VWS-Id
X-IPLB-Request-ID
X-LJ-Flow-ID
Section-Io-Id
X-Cache-Server
Mn-Server-Ip
Cross-Origin-Embedder-Policy
X-Locale
X-Frame-Option
X-Cluster
X-Cache-Host
X-Site-Version
X-Vcache
X-Reqid
X-Provided-By
Node
X-AB
X-Ms-Version
X-S
X-Geo-Region
X-Platform-Router
X-Is-Tablet
X-Is-Mobile
X-Browser-Name
X-Is-Supported-Browser
X-Is-Desktop
X-Ms-Request-Id
X-Proxied
X-Platform-Cluster
X-Platform-Processor
X-Extlb
AMP-Access-Control-Allow-Source-Origin
X-Forwarded-Host
X-Uri
X-Routing-Service
X-Tcp-Rtt
X-Zipkin-Id
X-Webstats-RespID
X-Xrds-Location
X-R9-Blue-Green-Version
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
Cache-Tv-Group
X-MP-GENERATED-AT
X-Sql-Count
X-TT-LOGID
X-Sql-Duration-Ms
WP-Super-Cache
Source
X-Origin-Date
Fastcgi-Useragent
CDN-PullZone
CDN-RequestPullSuccess
X-XRDS-Location
CDN-RequestPullCode
CDN-Uid
CDN-EdgeStorageId
CDN-Cache
CDN-RequestCountryCode
CDN-CachedAt
X-FB-TRIP-ID
X-Vcl-Version
Content-Secure-Policy
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Shopify-Stage
Priority
X-Sucuri-Cache
X-Use-Magma
X-Generated-By
X-Sucuri-ID
Onion-Location
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-ShopId
X-ShopId
Locale
X-Urbn-Site-Id
X-Content-Age
X-Cdn-Origin
X-Urbn-Context-Path
Sid
X-SRV
X-Newrelic-Synthetics
Cross-Origin-Embedder-Policy-Report-Only
S-Rt
WZWS-RAY
X-Pass-Why
X-Cluster-Node
X-Buckets
X-Shield-Cache-Expires
X-Thinkindot-L3
X-DataDome
X-CMSURLCustom
X-Scope-Id
TDXMobile
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
X-Varnish-Beresp-Ttl
X-LSADC-Cache
X-Cache-Action
Atl-Traceid
Cache
Cross-Origin-Window-Policy
X-Ua
X-Proxy-Cache-Status
X-Cache-Expired-At
X-GEO
HostName
X-COUNTRY
Edge-Copy-Time
X-WP-CF-Super-Cache-Cookies-Bypass
X-Via-SSL
X-Via-CDN
X-Via-Edge
X-A
X-Destination
X-PAYTM-SRV-ID
X-S-Cookie
Fastly-Drupal-HTML
X-A-Ccd
X-Rojux
X-Cache-Bucket
X-A-Wwc
X-Application
X-B-Cookie
X-Bc-Bl
X-BCube-Filmed-By
X-D
X-Aed
X-A-Dcw
X-A-Dgt
X-Developer
X-Conf
X-A-Dam
Type
X-Bl-Debug
Lang
Gannett-Cam-Experience-Id
DCR-Processing-Time-Ms
DCR-Decision-By
Redirect-Candidate
MD5-Digest
Origin-Agent-Cluster
Ngx.Var.Host
Ngx-Var-Key
Meta-Geo-Continent
CDCHOST
Rendered-Blocks
X-Ec-GeoHdr
X-Ec-Fail
X-Ec-Custom-Error
Origin
X-Epic-Correlation-Id
T-Server
X-External-Request-Id
Candidate-Md5Url
Sslversion
Surrogated-Key
X-Cache-NE
X-Optimistic-Header
X-SRCache-Key
X-Scheme
X-Vdms-Path
X-Vdms-Version
X-Viewer-Country
X-ScT
X-Vtex-Remote-Cache
X-TIM-N
X-Request-URI
X-Mg-Request-UUID
X-Aspnetmvc-Version
Fastly-SSL
Fastly-GeoIP-CountryCode
X-GeoIP-Region-Code
Apple-News-Services-Parsed-Url
X-GeoIP-Country-Code
Host-ID
X-Gdpr
Magicmarker
X-Generated-On
L
Environment
Apple-News-Services-Request-Url
X-Loc
Cluster
X-Human
X-Instance-Name
X-Forwarded-Site
X-Sigma-Backend
DSUID
Vix-Hermes-Req-Id
Server-Host
X-Level-Front-Cache
X-Fastly-Cache
X-Access
X-Varnishpool
X-Varnish-Director
X-Varnish-Beresp-Status
X-Correlation-ID
X-VG-WebCache
X-Clientip
X-VServer
X-Cache-Info
X-Bip
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Apple-News-Services-Host
X-TH-Server
Release
Pramga
Server-Ext
Server-Hostname
V-Age
X-Thanos
Ssr
Sever-Int
X-VCache
Req-ID
X-Pubstack
X-We-Are-Hiring
X-Dispatcher-Server
X-Op-Id-All
X-Sigma
X-Nyt-Route
X-Origin-Time
X-SD-PageType
Apple-News-Services-Handled
X-Proxied-Request
X-Pool
X-Request-Time
X-Rocket-Build-Number
X-Node-Id
X-Section
X-Request-Start
X-Platform
X-SB
X-Varnish-Hostname
User-Cache-Control
X-TimeS
X-Connection-Hash
X-Datadome
Expiry
X-Origin-Response-Time
X-V-Cache
Content-Style-Type
X-Device-Os
Content-Script-Type
X-Var-Ttl
Uber-Trace-Id
X-VG-TLSProxy
X-Req
X-Cache-Aspx
True-Client-Country-4JS
X-Request-Host
X-RateLimit-Remaining-Second
X-UA-Device-Type
X-Cache-Date
X-RateLimit-Limit-Second
Wxu-Next-Commit
X-WA-Info
X-ApacheServer
X-Acquia-Purge-Cdn-Unconfigured
X-Contensis-Viewer-Groups
X-TA-CDN-Provider
X-B3-Trace-ID
A
X-Auto-Login
X-NMSegId
X-Zen-Fury
X-BBC-Edge-Cache-Status
Web-Mar-Region
We-Hiring
X-Block-Status
Wxu-Next-Hostname
X-Mly-Id
X-Varnish-Authentication
Wxu-Next-Region
X-Gzip
X-FC-Vary-Parameters
X-Org
X-Geo-Header
X-GeoIP
X-SVT-ORM-RULES
X-Gen-Mode
Canary
Machine
X-GeoIP-City
X-NCache
X-GoCache-CacheStatus
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Cache-Id
X-Core-Value
Gh-Request-Id
X-Nginx-Cache-Key
X-Branch-Name
X-Men
X-Policy
X-Moov-Xdn-Version
On-Server
X-SVT-ORM-VERSION
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
Req-Svc-Chain
X-Server-IP
NM-Fastcgi-Cache
X-Hnp-Log
Cache-Provider
Mail-Subject
X-Esi-Check
X-PERF
C-Via
X-Moov-T
X-Service
X-Old-Content-Length
X-Wikidot-Backend
X-Hash
X-Micro-Cache
X-Fmm-Version
Platform
Producers
X-Up
Is-Eu
X-Fastly-Backend
X-Proto
Adler-Geo
X-From
X-Cache-TTL-Remaining
X-Amz-Meta-Cb-Modifiedtime
X-Wikidot-Static-Cache
X-Cdn-Srv
X-DPWN-IS-SECURE
Esi-Enabled
X-Ad-Load-Variation
X-App-Name
Tube-Return
Click-Count-Error
W
Tube-Got-Results
Tube-Got-Eval
X-DC
X-Dc
Country-Code
X-Aicache-OS
Tube-Get-Contents
Click-Count-Action-Start
Cache-Key
AKAMAI
X-Parent-Response-Time
X-Region-Sid
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
L5d-Success-Class
HA-Ipaddr
Fastly-Backend-Name
RNT-Time
RNT-Machine
Ha-Gx-Prefs
X-Ratelimit-Reset
Locid
Yak-Timeinfo
X-CacheTTL
Cf-Device-Type
X-Test
Proxy-Firewall
X-CGP
X-ND-Cache
X-Csrf-Jwt
X-AK-Request-ID
X-Eu-Site
Cdncip
Cdnsip
Pics-Label
X-Edge-Server
X-Tx-Id
NGX
Cdn-Request-Time
Cdn-Host
X-Accel-Expires-Debug
X-SIPLIST1
X-Owner
X-Date
X-Ah-Environment
Datacenter
X-Azure-Ref-OriginShield
X-HN
X-Core-Mission
IsBot
X-Amz-Storage-Class
PFcat
X-VarnishDD-TTL
X-ZONE
X-LB-ID
LB
X-Qloud-Router
X-Via-Poph
X-HA-Backend
X-Via-Popn
X-Via-Popv
X-Backend-Instance
XM
X-Refresh
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-LB-NoCache
X-CACHE-GROUP
X-DynaTrace-JS-Agent
Cdn
N-Cache
X-Tb-Optimization-Total-Bytes-Saved
Expect-Staple
X-Servedbyhost
X-Shop-Environment
NtCoent-Length
X-Tenant
X-NGINX-Cache
X-Cache-Type
X-Cache-Backend
X-API-Version
Xc-Version
X-Orig-Expires
X-Varnish-Hits
X-Origin-Expires
X-Forwarded-Path
X-VHOST
X-Lagoon
GeoIp-Country-Code
X-Wa
RATING
X-Nc
X-CDN-Cache-Status
SID
X-Gamma-Serve
Cdn-Requestid
X-ECache
X-Srv
CloudFront-Viewer-Country
CPC-Age
CPC-Cache
Cmstype
Cmsid
Server-ID
X-UA
X-Akamai-Transformed
X-Nananana
Resin-Trace
X-Zone
X-Cdn-Diag
X-Vmg-Version
X-Tt-Logid
X-Presslabs-Stats
X-Via-Fastly
X-Fpc
X-TX-ID
Cross-Origin-Opener-Policy-Report-Only
X-Hit
Uri
X-LAGOON
X-TIME
X-Proxy-CacheRZ
XkeyRZ
GeoIP-Latitude
User-Agent
X-B3-Parentspanid
Cache-Hits
CacheControlHeader
X-Nf-Request-Id
X-Client-Ip
X-RID
X-Api-Version
X-URL
X-Location
X-Ig-Origin-Region
X-Variation
X-NewRelic-App-Data
Fusion-Content-Id
Fusion-Template-Id
DataCenter
True-Client-Ip
X-Fastly-Country-Code
Fusion-Source
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Component-Id
X-Info
X-DataCenter
X-Amz-Meta-Opti
MIME-Version
Tcn
Powered-By
X-Cloudmap
True-Client-IP
Lb
X-Datacenter
VNS-Age
X-CACHE-AGE
VNS-Cache
X-NWS-UUID-VERIFY
X-HostName
X-B3-Spanid
Fastly-Drupal-Html
X-CUA
X-Geo
X-Jungle-Id
Origin-CC
X-CS
Origin-EX
Mime-Version
X-LiteSpeed-Tag
X-Dynatrace-Js-Agent
X-Cached-By
X-IAuth-Set-Uid
X-LiteSpeed-Cache-Control
X-User
Cf-Ipcountry
Hostname
Cache-Name
X-Webkit-Csp-Report-Only
X-Cdn-Forward
Debug
X-Segment-20210421
X-HOST
Srv
X-Vc
Load-Balancing
X-Varnish-Beresp-TTL
X-CSRF-TOKEN
X-Render-Time
X-Dispatcher-Number
X-AIR-PT
Cl-Cache
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Powered-By-VTEX-Cache
CDN
X-Mid
Edge-Cache
X-Auth-Group-Type
GeoIP-Country-Code
X-FPC
X-MCACHE
Server-Id
X-Wormhole-Sdk
X-Dispatch
X-Cdn-Cache-Status
Ohc-File-Size
X-Esi
X-Litespeed-Tag
X-Ig-Push-State
X-Oracle-DMS-ECID
X-NC
BehaviorPad-Version
X-Cs
X-WA
Ohc-Cache-HIT
X-APP-VERSION
Odigeo-Trace-Id
X-ServedByHost
X-NodeID
X-Lb-Nocache
X-Cache-Ttl
X-Fastly-Backend-Reqs
X-Vgn-Hpd-Reason
X-Custom-Header
X-Lb-Id
YJS-ID
X-Akamai-Pragma-Client-IP
CountryCode
X-Cache-Enabled
X-VCL-Version
Ms-Author-Via
X-Litespeed-Cache-Control
X-MiniProfiler-Ids
X-PHP-Backend
Xkeylog
Xkey-La3
X-Snapshot-Date
X-Via-PopV
Server-Info
X-Depends
X-Via-PopH
X-Via-PopN
X-Proxy-Cache-La3
Location
X-Ha-Backend
X-Cdn-Request-ID
X-MSEdge-Flight
X-MSEdge-Features
My-App
X-Pad
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Acquia-Site
Time
Memory
X-Acquia-Application-Trace
Memcached
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Srvid
X-FL-QIT-DEBUG
X-IN-APIGATEWAYSSL
Ngx
X-DefHash
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Internal-Host
CF-Ctrl
X-DefElseHash
X-Varnish-CookieHashed-On
X-IN-APIGATEWAY
X-FL-EDGE
FSS-Cache
CF-Cached-On
OriginIP
X-Shopid
Wpo-Cache-Status
X-Shardid
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Cache-Version
Wpo-Cache-Message
X-M-Reqid
X-M-Log
PICS-Label
Akamai-Cache-Status
Warning
X-Web-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
Geoip-Latitude
X-RequestId
X-Udemy-Cache-App-Namespace
X-Th-Server
X-Sucuri-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Lsadc-Cache
X-App
X-Nitro-Cache
X-Service-Response-Time
Section-Io-Origin-Status
X-Dw-Trace-Id
X-Mg-Cache
X-Serial
X-Check-Cacheable
X-Nitro-Cache-From
X-Nitro-Rev
Sm-Log-Id
X-Fastly-Cache-Hits