Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-Runtime
X-AspNet-Version
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Ua-Compatible
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
X-Dns-Prefetch-Control
Cf-Apo-Via
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
EagleEye-TraceId
X-WebKit-CSP
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-HW
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Litespeed-Cache
X-Trace
Content-Location
X-Url
Service-Worker-Allowed
X-Content-Type
X-Country
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-ECACHE
X-Edge
X-Origin-Cache-Key
Accept-Ch
X-Mcache
X-Mod-Pagespeed
Cross-Origin-Opener-Policy
X-Midtier
X-Amz-Server-Side-Encryption
X-Rack-Cache
Cache-Tag
X-FTR-Request-ID
Nginx-Cache
X-MS-InvokeApp
X-Upstream
X-PC
X-Vname
X-TtlSet
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-Browser-Type
X-D2id
X-Server-Name
X-Element-Page-Cache
X-Cdn-Fetch
Verso
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Id
X-B3-TraceId
X-Times
X-Cnection
X-Ac
SPIisLatency
SPRequestDuration
AR-SID
AR-PoweredBy
AR-ATIME
AR-Request-ID
X-Abt-Application-Version
X-Vcap-Request-Id
X-Navigation-Version
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-RateLimit-Remaining
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-GitHub-Request-Id
X-Ser
AR-CACHE
X-VARITI-CCR
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Mg-S
S
X-Cache-Key
RTSS
X-Middleton-Display
X-Sol
Display
Pagespeed
Edge-Cache-Tag
X-Ttl
X-NWS-LOG-UUID
X-Client-IP
X-Cache-TTL
X-Amz-Rid
X-Amzn-Trace-Id
Fastly-Restarts
Origin-Trial
X-Powered-CMS
X-Goog-Hash
X-Varnish-TTL
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Instrumentation
X-Server-ID
X-Version
X-Kinsta-Cache
Cache-Status
X-Edge-Location-Klb
Access-Control-Request-Method
X-Content-Security-Policy-Report-Only
X-Recruiting
X-ARC
X-TraceId
X-Content-Digest
Arr-Disable-Session-Affinity
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-MSEdge-Ref
Response
X-Forwarded-For
X-Middleton-Response
X-Ua-Device
Content-MD5
X-Accel-Expires
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
X-Id
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
Public-Key-Pins
X-FTR-Balancer
X-FTR-Backend
X-Request-Processing-Time
Server-Node
X-Request-Received
X-FTR-Expires
X-HS-Content-Id
MS-Author-Via
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
Payment
Front-End-Https
X-Ua-Browser
Cross-Origin-Resource-Policy
X-Webkit-Csp
X-DIS-Request-ID
X-RateLimit-Limit
X-Frontend
X-LLID
X-Forwarded-Proto
X-Daa-Tunnel
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-GUploader-UploadID
X-Fastcgi-Cache
X-FastCGI-Cache
TP-L2-Cache
Realpath
X-LB-Cache
X-Protected-By
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-Distributor
X-WebKit-CSP-Report-Only
X-Microsite
Count-Hit
X-Request-Handler-Origin-Region
X-Page-Id
X-ORACLE-DMS-RID
X-F-Cache
X-Az
X-Www-Served-By
X-NGENIX-Cache
X-AppVersion
X-Kinja-CCPA
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Activity-Id
MRF-Tech
X-Cluster-Name
X-Varnish-Backend
X-Hostname
X-Debug-Info
Accept-Charset
X-Geo-Country
Referer-Policy
X-Envoy-Decorator-Operation
X-App-Server
X-Correlation-Id
Host
X-Varnish-Server
X-Kong-Proxy-Latency
Fastcgi-Cache
X-Kong-Upstream-Latency
X-PressLabs-Stats
X-Goog-Metageneration
X-TTL
X-FB-Debug
Access-Control-Allow-Method
X-Git-Hash
X-ORACLE-DMS-ECID
X-RateLimit-Reset
Retry-After
X-Oracle-Dms-Ecid
X-XRDS-LOCATION
X-Rid
X-Ratelimit-Limit
X-CSRF-Token
Server-Name
X-Load-Cache
X-Content-Options
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Upgrade-Enabled
X-Aspnet-Duration-Ms
X-Contextid
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Px
X-Route-Name
DC
X-Revision
X-Signature
X-Grace
X-B-Cache
X-Trace-Id
X-App-Environment
X-Origin-Cache
X-Cache-Control
Paypal-Debug-Id
TCN
X-B
Charset
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Oracle-Dms-Rid
Section-Io-Cache
X-TT
Cleartype
X-Type
X-B3-Sampled
X-ASPNET-VERSION
X-Seen-By
X-Ezoic-Cdn
X-Amz-Meta-S3cmd-Attrs
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Mobile
X-Fastly-Request-ID
X-Fb-Rlafr
X-Amz-Replication-Status
Frame-Options
X-Whom
Healthy
X-Magnolia-Registration
X-Language
X-Wix-Request-Id
X-Logged-In
X-Goog-Stored-Content-Encoding
X-Fastly-Request-Id
X-Goog-Storage-Class
X-Goog-Generation
X-Node-Name
X-Goog-Stored-Content-Length
Filterid
X-EdgeConnect-Cache-Status
X-Azure-Ref
X-Proxy
X-Newrelic-App-Data
X-N
Content-Disposition
X-App-Version
Backend
X-Air-Pt
X-Varnish-Ttl
Akamai-GRN
Upgrade-Insecure-Requests
NGB
X-Template
Refresh
X-Proxy-Cache-Info
X-Original-Request-Id
X-Response-Served-From
X-Rendered-As
X-Is-Bot
X-Tumblr-Pixel-1
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Page-View
X-Unique-Id
X-Yottaa-Optimizations
SD-X-WS
X-RemovedCookies
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-ProcessESI
X-Tumblr-User
X-Yottaa-Metrics
X-Debug-IsConnected
X-Debug-IsPreview
X-WP-CF-Super-Cache-Cache-Control
Ms-Operation-Id
MS-CV
Viewport
X-Adobe-Content
X-Adobe-Loc
X-Servername
X-Amzn-Remapped-Content-Length
Liferay-Portal
X-Varnish-Grace
X-UUID
X-RTag
X-Datadog-Sampled
X-WP-CF-Super-Cache
Fastly-SWR
X-Debug
Fastly-SIE
X-B3-SpanId
X-FW-Type
X-FW-Server
X-Instance
X-FW-Version
X-FW-Static
X-FW-Serve
X-FW-Hash
X-G
X-IPS-LoggedIn
X-FW-Dynamic
X-Ratelimit-Remaining
X-Cacheable-TTL
X-Cache-Grace
X-Device-Type
X-User-Agent
Url
X-NYM-Debug-Backend
From-Origin
X-Rule
X-Region
X-Cache-Hit
Country
X-Jobs
X-Environment-Context
X-L-Path
X-Backend-Name
X-Hl-Ver
X-Status
Surrogate-Key
X-Webkit-CSP
ServerID
Countrycode
X-Air-Hostname
X-Air-Source
X-Cache-Age
X-Air-Trace-Id
X-Hosted-By
X-Time
X-Tec-Api-Origin
X-Origin-TTL
X-Tec-Api-Version
X-VC-Cache
X-Tec-Api-Root
Alternate-Protocol
X-Origin-CC
X-CCDN-CacheTTL
X-Content-Powered-By
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Cache-Status-Check
Amp-Access-Control-Allow-Source-Origin
X-Akamai-Request-ID2
X-Http-Reason
X-NODE
X-INCAP-ABP
X-HTML-Minification-Powered-By
X-Via-JSL
Protected
Version
X-Akamai-Edgescape
X-Rocket-Nginx-Serving-Static
WPO-Cache-Status
WPO-Cache-Message
GEO-INFO
X-Framework
X-Storage
CDN-RequestId
SRV
X-WP-CF-Super-Cache-Active
X-Accel-Version
X-CDN-Forward
Access-Control-Request-Headers
X-Cache-Rule
X-Edge-Location
X-Source
Front
CF-IPCountry
X-XRDS-Location
X-Nginx-Cache
X-Httpd
X-Real-IP
OT-Force-Account-Verify
X-Use-Magma
X-Use-Mantle
X-Mode
X-UPSTREAM-Address
X-Upstream-Ct
X-Cache-Operation
X-Upstream-Ht
Webserver
X-Rn-Rsrv
X-Rewrite-Enabled
X-VC
X-Endurance-Cache-Level
Accept-Language
Filters
X-Xfnlog-Site
Meta-Geo
X-JoinUs
X-Cache-Debug
Selected-Fe
X-Detected-As
X-Director
X-SaId
X-Served-From
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Proxy-Build
X-Soup
X-Timing-Wait
X-Varnish-Cache-Hits
X-Worker
ServedBy
X-Say-TTL
X-SayCDN-TTL
X-Sql-Duration-Ms
X-BYPASS-REASON
X-Cms-Context
X-Handled-By
X-Sql-Count
X-Say-Cacheable
X-ProxyCache-Status
X-Logging-Id
X-Origin
X-Redis-Cache
X-ProxyCache-Key
X-Adobe-Source
Webcakes-App-Version
Azure-Version
Webcakes-App-Name
Azure-SlotName
Azure-InstanceId
Azure-RegionName
Azure-SiteName
DB-Nickname
Webcakes-Region
TWC-Privacy
X-Varnish-Age
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
X-B3-Traceid
TWC-Connection-Speed
X-VCT
X-Cache-Time
TWC-Locale-Group
Web-Mar-Node
X-GeoCode
X-Tncms
X-RM-Cache-TTL
X-S
Xet-Cookie
X-Server-W
X-Lambda-Id
X-Labrador-Cache-Channel
X-Origin-Hint
X-No-Session
X-PHP-Host
X-Loop
X-GeoCountry
X-Varnish-Beresp-Grace
X-Skip-Cache
X-Cache-Server
X-Vercel-Cache
X-LJ-Flow-ID
X-Restarts
X-RCS-CacheZone
X-IPLB-Request-ID
X-Vercel-Id
AMP-Access-Control-Allow-Source-Origin
X-Format
X-VWS-Id
X-AWS-Id
X-Generation-Time
X-Tb
X-Fetched-On
X-IPLB-Instance
X-DynaTrace
X-Ms-Request-Id
X-Container-Uri
X-Provided-By
X-Geo-Region
Section-Io-Id
X-Browser-Name
X-Web-Node
X-Frame-Option
X-Git-Commit
X-Is-Tablet
X-Is-Supported-Browser
X-Tcp-Rtt
X-Is-Mobile
X-Is-Desktop
X-Ms-Version
X-Cluster
X-Reqid
Mn-Server-Ip
Node
X-AB
X-ServerID
Apigw-Requestid
X-R9-Blue-Green-Version
X-Routing-Service
Xserver
X-Locale
X-Zipkin-Id
X-Site-Version
X-Extlb
X-Proxied
X-Cache-Host
X-Uri
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-Forwarded-Host
Cache-Tv-Group
Cross-Origin-Embedder-Policy
X-COUNTRY
X-Webstats-RespID
Priority
X-Drupal-Cache-Contexts
X-FB-TRIP-ID
Source
X-Drupal-Cache-Tags
Fastcgi-Useragent
Content-Secure-Policy
X-Vcache
WP-Super-Cache
X-MP-GENERATED-AT
X-Origin-Date
X-Vcl-Version
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-PullZone
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
CDN-Uid
CDN-RequestPullSuccess
Onion-Location
X-Alternate-Cache-Key
X-Shopify-Stage
X-TT-LOGID
X-Storefront-Renderer-Rendered
Locale
X-Content-Age
X-Xrds-Location
X-Urbn-Context-Path
WZWS-RAY
X-Generated-By
X-SRV
X-Urbn-Site-Id
S-Rt
X-Sucuri-Cache
X-ShardId
X-Sorting-Hat-PodId
X-ShopId
X-Sorting-Hat-ShopId
X-Pass-Why
X-Sucuri-ID
X-Newrelic-Synthetics
X-Cdn-Origin
X-Ua
Sid
X-Buckets
X-Proxy-Cache-Status
X-Cluster-Node
X-Varnish-Beresp-Ttl
Cross-Origin-Embedder-Policy-Report-Only
X-Cache-Action
X-Scope-Id
X-Thinkindot-L3
X-Shield-Cache-Expires
Thinkindot-CacheControl
Thinkindot-Control
TDXMobile
Thinkindot-CacheControl-Type
X-VCache
X-CMSURLCustom
X-Cache-Expired-At
Cross-Origin-Window-Policy
Cache
X-LSADC-Cache
X-DataDome
Fastly-Drupal-HTML
X-GEO
HostName
Atl-Traceid
X-Mg-Request-UUID
X-Aspnetmvc-Version
X-Request-URI
X-Cache-Bucket
X-Bl-Debug
X-Aed
X-D
X-Destination
X-BCube-Filmed-By
X-A-Dcw
X-A-Dam
X-Conf
X-Application
X-A
X-Bc-Bl
X-A-Dgt
X-A-Ccd
X-Cache-NE
X-B-Cookie
X-Correlation-ID
X-Developer
X-Rojux
X-S-Cookie
Origin-Agent-Cluster
Redirect-Candidate
X-Vdms-Path
Lang
X-Vdms-Version
Rendered-Blocks
X-Scheme
X-ScT
Meta-Geo-Continent
X-TIM-N
MD5-Digest
Ngx-Var-Key
X-SRCache-Key
Candidate-Md5Url
Origin
Ngx.Var.Host
X-Viewer-Country
Gannett-Cam-Experience-Id
DCR-Decision-By
X-A-Wwc
Type
T-Server
X-External-Request-Id
X-Epic-Correlation-Id
DCR-Processing-Time-Ms
X-Ec-Custom-Error
X-Ec-Fail
X-Ec-GeoHdr
X-PAYTM-SRV-ID
Surrogated-Key
X-Vtex-Remote-Cache
Sslversion
X-Optimistic-Header
Environment
X-Datadome
X-WP-CF-Super-Cache-Cookies-Bypass
X-TimeS
X-Via-Edge
X-Via-SSL
X-Via-CDN
Edge-Copy-Time
Host-ID
Fastly-GeoIP-CountryCode
DSUID
Pramga
Sever-Int
Ssr
V-Age
Vix-Hermes-Req-Id
Server-Hostname
Server-Host
Release
Req-ID
Req-Svc-Chain
Server-Ext
Magicmarker
X-Dispatcher-Server
X-Rocket-Build-Number
X-SB
X-SD-PageType
X-Sigma
X-Request-Time
X-Request-Start
X-Pool
X-Proxied-Request
X-Pubstack
X-Req
X-Sigma-Backend
X-TH-Server
X-VG-WebCache
X-VServer
X-WA-Info
X-We-Are-Hiring
X-VG-TLSProxy
X-Varnishpool
X-Thanos
X-Varnish-Beresp-Status
X-Varnish-Director
X-Varnish-Hostname
X-Platform
X-Origin-Time
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Fastly-Cache
X-Forwarded-Site
X-Core-Value
X-Clientip
X-Aicache-OS
X-BBC-Edge-Cache-Status
X-Bip
X-Cache-Info
X-Gdpr
X-Generated-On
X-Mly-Id
X-Node-Id
X-Nyt-Route
X-Op-Id-All
X-Loc
X-Level-Front-Cache
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Human
X-Instance-Name
X-Acquia-Purge-Cdn-Unconfigured
X-B3-Trace-ID
CDCHOST
User-Cache-Control
X-Origin-Response-Time
X-Micro-Cache
Tube-Got-Results
Tube-Return
Uber-Trace-Id
X-Hnp-Log
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Men
Tube-Got-Eval
X-Mvc-Supplant-Cachable
X-NMSegId
X-Cache-Date
X-TA-CDN-Provider
Apple-News-Services-Handled
Adler-Geo
X-Nginx-Cache-Key
We-Hiring
X-Mvc-Supplant-OutputCached
X-NCache
Tube-Get-Contents
Web-Mar-Region
X-Esi-Check
X-ApacheServer
X-FC-Vary-Parameters
X-Fmm-Version
X-Auto-Login
X-DPWN-IS-SECURE
X-Cache-Id
X-Block-Status
X-Cache-TTL-Remaining
X-Device-Os
X-Ad-Load-Variation
X-From
X-Gzip
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-GeoIP-City
X-GeoIP
X-Access
X-Gen-Mode
X-Geo-Header
Apple-News-Services-Host
X-Old-Content-Length
Mail-Subject
X-Var-Ttl
X-Org
X-V-Cache
X-Up
X-SVT-ORM-VERSION
X-UA-Device-Type
Click-Count-Action-Start
X-Zen-Fury
Gh-Request-Id
Fastly-SSL
Esi-Enabled
Click-Count-Error
Is-Eu
L
Cluster
X-SVT-ORM-RULES
Machine
C-Via
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Country-Code
Apple-News-Services-Parsed-Url
X-PERF
X-Policy
Producers
Apple-News-Services-Request-Url
On-Server
X-Server-IP
NM-Fastcgi-Cache
X-Section
Canary
Platform
X-Request-Host
X-Connection-Hash
X-DC
X-Service
Expiry
X-Core-Mission
Content-Style-Type
A
Content-Script-Type
X-Branch-Name
X-Cdn-Srv
X-Fastly-Backend
X-Contensis-Viewer-Groups
X-Cache-Aspx
X-SIPLIST1
X-GoCache-CacheStatus
X-Hash
X-Test
X-Edge-Server
X-Varnish-Authentication
X-ZONE
X-Proto
Cdn-Host
Cdn-Request-Time
Cache-Provider
AKAMAI
X-App-Name
True-Client-Country-4JS
IsBot
Cf-Device-Type
X-Parent-Response-Time
Proxy-Firewall
Pics-Label
X-Wikidot-Static-Cache
Fastly-Backend-Name
RNT-Machine
X-Amz-Meta-Cb-Modifiedtime
X-HA-Backend
W
RNT-Time
X-Wikidot-Backend
X-Slack-Backend
X-Via-Popn
X-Via-Popv
Cache-Key
X-Moov-Xdn-Version
X-Via-Poph
X-Ah-Environment
X-Slack-Shared-Secret-Outcome
X-Sn-Servicetimems
NGX
X-Moov-T
X-Dc
X-CacheTTL
X-NGINX-Cache
Datacenter
Locid
X-Region-Sid
X-Accel-Expires-Debug
Cdncip
Expect-Staple
N-Cache
HA-Ipaddr
X-CF-Lambda-Fn
Ha-Gx-Prefs
X-CF-Lambda-Version
L5d-Success-Class
X-CGP
Cdnsip
X-Eu-Site
X-ND-Cache
LB
X-AK-Request-ID
X-Csrf-Jwt
X-Qloud-Router
Yak-Timeinfo
X-Owner
X-Date
X-Orig-Expires
X-LB-NoCache
X-Cache-Type
X-Shop-Environment
Xc-Version
X-Forwarded-Path
X-LB-ID
X-Tenant
X-Amz-Storage-Class
X-Ratelimit-Reset
Cdn
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Hits
X-Refresh
X-Tx-Id
PFcat
X-Azure-Ref-OriginShield
X-HN
X-VarnishDD-TTL
X-Backend-Instance
X-Gamma-Serve
X-VHOST
SID
X-Tt-Logid
X-CDN-Cache-Status
X-Servedbyhost
RATING
Cmstype
X-Wa
X-Nc
X-DynaTrace-JS-Agent
GeoIp-Country-Code
NtCoent-Length
Cmsid
Cdn-Requestid
XM
CPC-Age
CPC-Cache
X-Vmg-Version
X-Origin-Expires
X-API-Version
X-Cdn-Diag
Server-ID
X-TX-ID
X-Cache-Backend
X-Srv
X-TIME
X-Lagoon
X-Akamai-Transformed
X-LAGOON
X-Via-Fastly
X-Nananana
X-Fpc
CloudFront-Viewer-Country
X-Api-Version
CacheControlHeader
Resin-Trace
X-B3-Parentspanid
X-Hit
X-NewRelic-App-Data
X-Zone
X-Proxy-CacheRZ
Cross-Origin-Opener-Policy-Report-Only
User-Agent
X-Variation
Uri
XkeyRZ
X-Nf-Request-Id
X-Client-Ip
X-UA
X-URL
X-CACHE-AGE
X-Presslabs-Stats
MIME-Version
X-Info
X-Amz-Meta-Opti
X-Fastly-Country-Code
Tcn
X-LiteSpeed-Tag
VNS-Age
VNS-Cache
Cache-Hits
True-Client-IP
X-Datacenter
Lb
True-Client-Ip
GeoIP-Latitude
X-Ig-Origin-Region
X-Location
X-Dynatrace-Js-Agent
DataCenter
X-LiteSpeed-Cache-Control
X-HostName
Mime-Version
X-NWS-UUID-VERIFY
Fusion-Template-Id
Fusion-Deployment-Id
Cache-Name
Fusion-Source
X-Geo
Fusion-Content-Source
Fusion-Content-Id
X-DataCenter
X-Vc
Fusion-Component-Id
X-RID
Cf-Ipcountry
Powered-By
Hostname
Fastly-Drupal-Html
X-B3-Spanid
X-CUA
X-Jungle-Id
Origin-EX
Origin-CC
X-Cloudmap
X-HOST
X-Cached-By
X-Dispatcher-Number
X-Cdn-Forward
X-CSRF-TOKEN
X-IAuth-Set-Uid
X-AIR-PT
X-Segment-20210421
X-User
X-CS
Srv
X-Webkit-Csp-Report-Only
X-Mid
Debug
X-Varnish-Beresp-TTL
X-Render-Time
X-MCACHE
X-ECache
Load-Balancing
X-Powered-By-VTEX-Cache
GeoIP-Country-Code
X-Wormhole-Sdk
X-Dispatch
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Esi
CDN
X-FPC
Ohc-File-Size
Cl-Cache
BehaviorPad-Version
X-Litespeed-Tag
X-ServedByHost
X-Cdn-Cache-Status
X-Cs
Server-Id
X-WA
X-Oracle-DMS-ECID
X-NC
X-Auth-Group-Type
Edge-Cache
Ohc-Cache-HIT
X-Lb-Id
X-Cache-Enabled
YJS-ID
X-Lb-Nocache
X-Fastly-Backend-Reqs
X-Wp-Cf-Super-Cache
Server-Info
X-Wp-Cf-Super-Cache-Cache-Control
My-App
X-Ig-Push-State
Location
CountryCode
X-VCL-Version
X-Litespeed-Cache-Control
Wpo-Cache-Message
Wpo-Cache-Status
Ms-Author-Via
X-NodeID
X-MiniProfiler-Ids
Xkey-La3
Xkeylog
X-Snapshot-Date
X-Proxy-Cache-La3
Odigeo-Trace-Id
X-Cdn-Request-ID
X-APP-VERSION
X-Internal-Host
CF-Cached-On
CF-Ctrl
X-MSEdge-Features
X-Akamai-Pragma-Client-IP
X-MSEdge-Flight
Time
X-Custom-Header
Memory
Section-Origin-Responded
X-Pad
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Memcached
OriginIP
X-FL-EDGE
X-Nitro-Rev
X-Acquia-Site
X-Acquia-Purge-Tags
Section-Io-Origin-Time-Seconds
X-Vgn-Hpd-Reason
X-Nitro-Cache
X-Nitro-Cache-From
X-Acquia-Application-UUID
FSS-Cache
Srvid
X-App
Section-Io-Origin-Status
X-FL-QIT-DEBUG
Ngx
Geoip-Latitude
X-Acquia-Application-Trace
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Cache-Version
X-Shopid
X-Shardid
Cloudfront-Viewer-Country
X-Depends
Akamai-Cache-Status
X-Mg-Cache
X-PHP-Backend
X-Cache-FS-Status
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Fastly-Cache-Hits
X-Http-Count
X-Ha-Backend
X-Te-Count
X-Te-Duration-Ms
X-Http-Duration-Ms
X-Lsadc-Cache
X-Sucuri-Id
X-Check-Cacheable
X-Serial
X-Service-Response-Time
X-Web-Server
Sm-Log-Id
X-Udemy-Cache-App-Namespace
X-Th-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-RequestId
X-Dw-Trace-Id