Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-Served-By
X-UA-Compatible
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-Runtime
X-AspNet-Version
Accept-CH
X-Ua-Compatible
X-Cache-Status
X-DNS-Prefetch-Control
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
X-Rq
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-Varnish-Cache
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-CST
X-WebKit-CSP
X-Backend-Server
X-OneAgent-JS-Injection
Permissions-Policy
Accept-Ch-Lifetime
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Cache-Lookup
X-Oneagent-Js-Injection
X-Litespeed-Cache
X-Trace
Content-Location
X-Ruxit-JS-Agent
X-Url
Service-Worker-Allowed
X-Content-Type
X-Country
X-Clacks-Overhead
X-ECACHE
X-Edge
X-Origin-Cache-Key
X-Mcache
Accept-Ch
X-Mod-Pagespeed
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Midtier
X-FTR-Request-ID
X-Rack-Cache
Cache-Tag
X-MS-InvokeApp
Nginx-Cache
X-Upstream
X-TtlSet
X-Vname
X-ESI
X-PC
X-Powered-By-Plesk
Rating
Edge-Control
X-Browser-Type
X-D2id
X-Server-Name
Verso
X-Element-Page-Cache
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
X-Kinja
X-Cdn-Fetch
X-Times
X-Cnection
X-Ruxit-Js-Agent
X-Ac
SPIisLatency
SPRequestDuration
X-B3-TraceId
AR-Request-ID
AR-SID
AR-PoweredBy
AR-ATIME
X-Vcap-Request-Id
X-Abt-Application-Version
X-SharePointHealthScore
X-Navigation-Version
SPRequestGuid
X-RateLimit-Remaining
X-NF-Request-ID
X-Dw-Request-Base-Id
X-ASPNET-VERSION
X-GitHub-Request-Id
X-Ser
AR-CACHE
X-VARITI-CCR
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Mg-S
S
X-Cache-Key
Display
Pagespeed
X-Middleton-Display
X-Sol
RTSS
X-NWS-LOG-UUID
X-Client-IP
Edge-Cache-Tag
X-Ttl
X-Cache-TTL
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Powered-CMS
Origin-Trial
X-Goog-Hash
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kinsta-Cache
X-Edge-Location-Klb
X-Version
X-Server-ID
Cache-Status
Access-Control-Request-Method
X-Content-Security-Policy-Report-Only
X-Varnish-TTL
X-Recruiting
X-ARC
X-TraceId
X-Webkit-Csp
X-Content-Digest
Arr-Disable-Session-Affinity
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-T
X-SRCache-Fetch-Status
X-MSEdge-Ref
X-SRCache-Store-Status
X-Forwarded-For
Response
X-Middleton-Response
X-Ua-Device
Content-MD5
X-Accel-Expires
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Cached
X-RateLimit-Limit
X-Hits
X-Id
X-Fastcgi-Cache
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
Public-Key-Pins
X-FTR-Expires
Server-Node
MS-Author-Via
X-Request-Received
X-Request-Processing-Time
X-HS-Cache-Config
X-HS-Combine-CSS
Payment
X-HS-Hub-Id
X-HS-Content-Id
X-Ua-Browser
Front-End-Https
Cross-Origin-Resource-Policy
X-DIS-Request-ID
X-Frontend
X-Forwarded-Proto
X-LLID
X-Daa-Tunnel
X-Jurisdiction
X-GUploader-UploadID
X-HP-Webp
X-HP-Trace-Id
TP-L2-Cache
Realpath
X-LB-Cache
X-Protected-By
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-WebKit-CSP-Report-Only
X-Distributor
Count-Hit
X-Request-Handler-Origin-Region
X-Microsite
X-FastCGI-Cache
X-Page-Id
X-ORACLE-DMS-RID
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Kinja-CCPA
X-Www-Served-By
X-F-Cache
X-NGENIX-Cache
X-Az
X-AppVersion
X-Activity-Id
X-Cluster-Name
Referer-Policy
X-Hostname
Accept-Charset
X-Varnish-Backend
X-Debug-Info
X-Geo-Country
X-App-Server
X-Envoy-Decorator-Operation
X-Correlation-Id
Fastcgi-Cache
X-PressLabs-Stats
X-Varnish-Server
Host
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-TTL
X-Goog-Metageneration
X-FB-Debug
Access-Control-Allow-Method
X-Rid
X-Git-Hash
X-ORACLE-DMS-ECID
X-RateLimit-Reset
X-Oracle-Dms-Ecid
Retry-After
X-XRDS-LOCATION
Server-Name
X-CSRF-Token
X-Content-Options
X-Load-Cache
X-Px
X-Upgrade-Enabled
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Is-Crawler
X-Flags
X-Request-Guid
X-Contextid
X-Route-Name
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Revision
DC
X-Trace-Id
X-Origin-Cache
TCN
Charset
X-Cache-Control
X-Grace
X-App-Environment
X-B
X-Signature
X-Datadog-Parent-Id
X-B-Cache
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
Paypal-Debug-Id
X-Type
X-Seen-By
Section-Io-Cache
X-B3-Sampled
Cleartype
X-TT
X-Ezoic-Cdn
X-Oracle-Dms-Rid
X-Amz-Meta-S3cmd-Attrs
X-Mobile
X-Fastly-Request-ID
X-Ratelimit-Limit
X-Fb-Rlafr
Frame-Options
X-Amz-Replication-Status
Healthy
X-Wix-Request-Id
X-Language
X-Magnolia-Registration
X-Varnish-Ttl
X-Whom
X-Logged-In
X-Node-Name
X-Goog-Storage-Class
X-Goog-Generation
X-Fastly-Request-Id
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Filterid
X-EdgeConnect-Cache-Status
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Azure-Ref
X-Proxy
X-App-Version
X-Newrelic-App-Data
X-N
Content-Disposition
Backend
Akamai-GRN
X-Template
Refresh
X-Air-Pt
NGB
Upgrade-Insecure-Requests
X-Proxy-Cache-Info
X-Response-Served-From
X-Original-Request-Id
X-Is-Bot
X-Rendered-As
X-Tumblr-User
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Unique-Id
SD-X-WS
X-Yottaa-Metrics
X-RemovedCookies
X-Page-View
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel-0
X-ProcessESI
X-Tumblr-Pixel-1
Liferay-Portal
X-UUID
X-Varnish-Grace
Viewport
X-RTag
Ms-Operation-Id
X-Adobe-Content
X-Adobe-Loc
X-Instance
X-Amzn-Remapped-Content-Length
MS-CV
X-Debug-IsPreview
X-Servername
X-Datadog-Sampled
X-WP-CF-Super-Cache-Cache-Control
X-Debug-IsConnected
X-WP-CF-Super-Cache
X-Debug
X-G
X-IPS-LoggedIn
X-FW-Serve
X-FW-Dynamic
X-FW-Hash
X-FW-Static
Fastly-SWR
X-FW-Version
X-FW-Server
Fastly-SIE
X-FW-Type
X-Ratelimit-Remaining
X-Device-Type
X-User-Agent
X-Cacheable-TTL
Url
X-Region
X-NYM-Debug-Backend
X-Cache-Grace
From-Origin
X-Rule
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Country
X-Environment-Context
X-Cache-Hit
X-Jobs
X-L-Path
X-Hl-Ver
X-Status
X-Backend-Name
X-B3-SpanId
ServerID
X-Webkit-CSP
Surrogate-Key
Countrycode
X-Air-Trace-Id
X-Air-Source
X-Cache-Age
X-Air-Hostname
X-Hosted-By
X-Time
X-VC-Cache
Alternate-Protocol
X-Origin-TTL
X-Origin-CC
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Content-Powered-By
X-Http-Reason
X-Akamai-Request-ID2
X-NODE
Amp-Access-Control-Allow-Source-Origin
X-Cache-Status-Check
X-Via-JSL
Protected
X-INCAP-ABP
X-HTML-Minification-Powered-By
WPO-Cache-Status
WPO-Cache-Message
X-B3-Traceid
Version
SRV
X-Akamai-Edgescape
X-Rocket-Nginx-Serving-Static
X-CDN-Forward
GEO-INFO
X-Nginx-Cache
CF-IPCountry
X-Framework
X-Storage
X-WP-CF-Super-Cache-Active
X-Edge-Location
X-Source
X-Accel-Version
X-Cache-Rule
Access-Control-Request-Headers
X-XRDS-Location
Front
CDN-RequestId
X-Httpd
X-Mode
X-Real-IP
X-Use-Magma
OT-Force-Account-Verify
X-Use-Mantle
Accept-Language
X-Xfnlog-Site
X-Upstream-Ht
X-Upstream-Ct
X-Rewrite-Enabled
X-Cache-Operation
Filters
X-VC
Webserver
X-Rn-Rsrv
X-UPSTREAM-Address
Meta-Geo
X-Endurance-Cache-Level
X-Proxy-Build
Selected-Fe
X-Served-From
X-JoinUs
X-Director
X-Cache-Debug
X-Detected-As
X-Soup
X-SaId
X-Tumblr-Pixel-2
X-Timing-Wait
X-Tumblr-Pixel-3
X-Handled-By
X-Varnish-Cache-Hits
X-Worker
ServedBy
X-Adobe-Source
X-BYPASS-REASON
X-Cms-Context
X-Logging-Id
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Sql-Duration-Ms
X-ProxyCache-Status
X-Origin
X-ProxyCache-Key
X-Sql-Count
X-Redis-Cache
Webcakes-App-Version
TWC-Connection-Speed
X-GeoCountry
Webcakes-App-Name
X-Labrador-Cache-Channel
X-Loop
Web-Mar-Node
X-Lambda-Id
X-GeoCode
Webcakes-Region
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Format
DB-Nickname
X-Cache-Time
X-No-Session
X-VCT
TWC-GeoIP-LatLong
X-Varnish-Age
TWC-GeoIP-Country
Property-Id
Xet-Cookie
Xserver
TWC-Device-Class
X-Origin-Hint
X-Tncms
AMP-Access-Control-Allow-Source-Origin
TWC-Privacy
X-PHP-Host
X-Restarts
X-RM-Cache-TTL
X-Server-W
TWC-Locale-Group
X-S
X-Cache-Server
X-AWS-Id
X-Git-Commit
X-Varnish-Beresp-Grace
X-Tb
X-Vercel-Cache
X-Vercel-Id
X-VWS-Id
X-RCS-CacheZone
X-LJ-Flow-ID
X-Fetched-On
X-DynaTrace
X-Generation-Time
X-IPLB-Instance
X-IPLB-Request-ID
X-Container-Uri
X-Skip-Cache
Apigw-Requestid
Mn-Server-Ip
X-Is-Tablet
X-Is-Supported-Browser
X-Ms-Request-Id
X-Browser-Name
X-ServerID
X-Is-Mobile
X-Cache-Host
X-Frame-Option
X-Geo-Region
X-Is-Desktop
X-Ms-Version
X-Cluster
X-Provided-By
X-AB
X-Web-Node
Section-Io-Id
X-Tcp-Rtt
Node
X-Reqid
X-Proxied
X-Extlb
X-Forwarded-Host
X-Locale
X-R9-Blue-Green-Version
X-Routing-Service
X-Site-Version
X-Zipkin-Id
X-Platform-Router
X-Uri
Cache-Tv-Group
Cross-Origin-Embedder-Policy
X-Platform-Processor
X-Platform-Cluster
X-Webstats-RespID
X-COUNTRY
X-Drupal-Cache-Tags
Source
X-FB-TRIP-ID
X-Drupal-Cache-Contexts
Priority
Content-Secure-Policy
Fastcgi-Useragent
X-Vcache
X-MP-GENERATED-AT
WP-Super-Cache
X-Origin-Date
X-Vcl-Version
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-Uid
CDN-RequestPullSuccess
CDN-PullZone
X-Alternate-Cache-Key
Onion-Location
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Urbn-Context-Path
X-Content-Age
Locale
X-Urbn-Site-Id
WZWS-RAY
X-Xrds-Location
X-Generated-By
X-Pass-Why
X-ShardId
X-Sucuri-Cache
S-Rt
X-Sorting-Hat-ShopId
X-ShopId
X-Sorting-Hat-PodId
X-Sucuri-ID
X-Cdn-Origin
X-Newrelic-Synthetics
X-TT-LOGID
X-Ua
X-SRV
Sid
X-Cluster-Node
X-Varnish-Beresp-Ttl
X-Buckets
X-Proxy-Cache-Status
Cross-Origin-Embedder-Policy-Report-Only
X-Cache-Action
X-Cache-Expired-At
X-Shield-Cache-Expires
X-Scope-Id
X-Thinkindot-L3
Thinkindot-CacheControl
TDXMobile
Cross-Origin-Window-Policy
Thinkindot-CacheControl-Type
X-VCache
X-CMSURLCustom
Thinkindot-Control
X-LSADC-Cache
Cache
X-DataDome
HostName
Atl-Traceid
Fastly-Drupal-HTML
X-Mg-Request-UUID
X-Via-SSL
X-Request-URI
X-Via-CDN
X-Aspnetmvc-Version
Edge-Copy-Time
X-Via-Edge
X-SRCache-Key
Lang
X-Optimistic-Header
X-Vdms-Version
Meta-Geo-Continent
X-Vdms-Path
X-Cache-NE
MD5-Digest
X-TIM-N
Rendered-Blocks
X-A-Dam
Environment
X-Bc-Bl
X-A-Dcw
X-B-Cookie
X-A-Dgt
X-Application
X-BCube-Filmed-By
X-A-Ccd
Sslversion
X-Aed
DCR-Processing-Time-Ms
X-Cache-Bucket
X-Bl-Debug
Gannett-Cam-Experience-Id
DCR-Decision-By
X-Conf
CDCHOST
X-A
X-S-Cookie
Type
T-Server
X-Scheme
Ngx-Var-Key
Candidate-Md5Url
X-Vtex-Remote-Cache
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
Redirect-Candidate
X-A-Wwc
X-Viewer-Country
X-Rojux
X-Ec-Custom-Error
X-Ec-Fail
X-Correlation-ID
Origin
X-Destination
Surrogated-Key
X-Developer
Origin-Agent-Cluster
X-PAYTM-SRV-ID
Ngx.Var.Host
X-D
X-ScT
X-WP-CF-Super-Cache-Cookies-Bypass
X-Datadome
X-GEO
X-TimeS
Release
Host-ID
V-Age
Server-Hostname
Vix-Hermes-Req-Id
Pramga
L
Req-ID
Server-Host
X-We-Are-Hiring
Magicmarker
Sever-Int
Server-Ext
Ssr
Fastly-SSL
X-Debug-Cache-Fetch
X-Varnish-Director
X-Varnish-Hostname
X-Varnish-Beresp-Status
X-Sigma
X-Platform
X-Level-Front-Cache
X-Pool
X-Forwarded-Site
X-Proxied-Request
X-Instance-Name
Fastly-GeoIP-CountryCode
X-Gdpr
X-Sigma-Backend
X-Mly-Id
X-Node-Id
X-TH-Server
X-Loc
X-Thanos
X-Nyt-Route
X-Op-Id-All
X-Origin-Time
X-Generated-On
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Pubstack
X-Req
X-Core-Value
X-Clientip
X-SD-PageType
X-Debug-Cache-Store
X-Dispatcher-Server
X-Cache-Info
X-Bip
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Section
X-WA-Info
X-VG-WebCache
X-VG-TLSProxy
X-Request-Start
X-Varnishpool
X-Request-Time
X-Human
X-SB
X-Fastly-Cache
X-VServer
X-Rocket-Build-Number
X-Access
Req-Svc-Chain
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Origin-Response-Time
Apple-News-Services-Host
DSUID
User-Cache-Control
X-Var-Ttl
X-Cache-TTL-Remaining
X-Cache-Date
X-V-Cache
X-Cache-Id
X-Zen-Fury
X-DPWN-IS-SECURE
X-Device-Os
X-UA-Device-Type
X-Esi-Check
X-Up
Uber-Trace-Id
X-Ad-Load-Variation
Wxu-Next-Region
Web-Mar-Region
Wxu-Next-Hostname
X-ApacheServer
X-Auto-Login
Wxu-Next-Commit
We-Hiring
X-SVT-ORM-VERSION
Cluster
X-Fmm-Version
X-Mvc-Supplant-OutputCached
X-RateLimit-Limit-Second
X-Mvc-Supplant-Cachable
X-RateLimit-Remaining-Second
X-Men
X-Micro-Cache
X-NCache
X-Nginx-Cache-Key
X-PERF
X-Org
X-Old-Content-Length
X-Policy
X-NMSegId
X-Request-Host
X-Irp-Debug
X-Gen-Mode
X-Geo-Header
X-From
X-SVT-ORM-RULES
Tube-Return
X-GeoIP
X-GeoIP-City
X-Server-IP
X-TA-CDN-Provider
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Gzip
X-FC-Vary-Parameters
X-Block-Status
C-Via
Country-Code
Click-Count-Action-Start
NM-Fastcgi-Cache
Is-Eu
Platform
Click-Count-Error
Mail-Subject
Cache-Provider
Machine
On-Server
Producers
Esi-Enabled
Gh-Request-Id
Tube-Get-Contents
Tube-Got-Eval
True-Client-Country-4JS
Adler-Geo
Tube-Got-Results
Canary
X-Connection-Hash
X-DC
Expiry
X-Service
X-Hash
Cdn-Host
Cdn-Request-Time
X-Fastly-Backend
X-SIPLIST1
X-ZONE
Cf-Device-Type
X-Edge-Server
X-Core-Mission
X-Cdn-Srv
Pics-Label
X-App-Name
Content-Style-Type
Content-Script-Type
X-Branch-Name
A
W
X-Proto
AKAMAI
IsBot
X-Moov-T
X-GoCache-CacheStatus
X-Moov-Xdn-Version
X-Cache-Aspx
X-Test
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Parent-Response-Time
X-Dc
L5d-Success-Class
X-Amz-Meta-Cb-Modifiedtime
HA-Ipaddr
Fastly-Backend-Name
Ha-Gx-Prefs
X-HA-Backend
X-Slack-Backend
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
NGX
X-Ah-Environment
X-Eu-Site
Proxy-Firewall
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-CacheTTL
X-Via-Popn
X-Via-Popv
Cache-Key
X-CGP
X-Via-Poph
X-Csrf-Jwt
RNT-Time
RNT-Machine
Datacenter
X-AK-Request-ID
Cdnsip
X-Owner
Expect-Staple
Cdn
X-LB-NoCache
N-Cache
X-Qloud-Router
X-Region-Sid
Locid
X-Accel-Expires-Debug
Cdncip
X-ND-Cache
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Date
LB
Yak-Timeinfo
X-Orig-Expires
X-Amz-Storage-Class
X-VarnishDD-TTL
X-LB-ID
Cdn-Requestid
X-Tt-Logid
X-Tenant
X-Forwarded-Path
PFcat
X-HN
X-Cache-Type
X-Shop-Environment
Xc-Version
X-Ratelimit-Reset
X-Gamma-Serve
X-Backend-Instance
X-Azure-Ref-OriginShield
X-Tb-Optimization-Total-Bytes-Saved
X-Refresh
X-Servedbyhost
X-NGINX-Cache
X-Varnish-Hits
X-Tx-Id
X-VHOST
GeoIp-Country-Code
X-DynaTrace-JS-Agent
Cmsid
Server-ID
RATING
X-Wa
XM
SID
X-Nc
X-CDN-Cache-Status
Cmstype
NtCoent-Length
X-Srv
X-Origin-Expires
X-Cdn-Diag
CPC-Cache
X-Cache-Backend
X-API-Version
X-Vmg-Version
CPC-Age
X-TX-ID
X-Nananana
X-Fpc
CloudFront-Viewer-Country
X-TIME
X-Akamai-Transformed
X-Lagoon
X-LAGOON
X-Via-Fastly
X-Api-Version
X-NewRelic-App-Data
X-Hit
X-B3-Parentspanid
CacheControlHeader
X-Zone
X-Proxy-CacheRZ
XkeyRZ
Cross-Origin-Opener-Policy-Report-Only
User-Agent
Resin-Trace
X-Variation
Uri
X-Nf-Request-Id
X-Client-Ip
X-UA
X-CACHE-AGE
X-URL
X-Presslabs-Stats
X-Info
True-Client-Ip
X-Fastly-Country-Code
X-Amz-Meta-Opti
X-Datacenter
MIME-Version
Tcn
X-LiteSpeed-Tag
X-Geo
VNS-Age
Cache-Hits
X-Ig-Origin-Region
Lb
GeoIP-Latitude
X-B3-Spanid
X-Location
VNS-Cache
X-Dynatrace-Js-Agent
X-LiteSpeed-Cache-Control
DataCenter
X-HostName
Fusion-Template-Id
X-NWS-UUID-VERIFY
Mime-Version
Fusion-Content-Source
Fusion-Content-Id
X-Vc
Fusion-Deployment-Id
Fusion-Component-Id
True-Client-IP
Fusion-Source
X-DataCenter
Cache-Name
X-AIR-PT
Hostname
Powered-By
Fastly-Drupal-Html
X-Cloudmap
X-Jungle-Id
X-HOST
Origin-CC
X-CUA
Origin-EX
X-Cached-By
X-Dispatcher-Number
X-CSRF-TOKEN
X-User
X-Segment-20210421
X-IAuth-Set-Uid
X-CS
Cf-Ipcountry
X-RID
X-Webkit-Csp-Report-Only
X-Cdn-Forward
Debug
X-Mid
Srv
X-MCACHE
Cl-Cache
X-Render-Time
X-ECache
X-Wormhole-Sdk
Load-Balancing
X-Varnish-Beresp-TTL
X-VTEX-Cache-Time
X-Dispatch
GeoIP-Country-Code
BehaviorPad-Version
Ohc-File-Size
X-VTEX-Cache-Server
X-Esi
X-Powered-By-VTEX-Cache
X-Litespeed-Tag
X-Cs
Edge-Cache
X-FPC
X-Oracle-DMS-ECID
X-WA
X-Auth-Group-Type
X-Cdn-Cache-Status
X-NC
CDN
Ohc-Cache-HIT
Server-Id
X-Cache-Enabled
YJS-ID
X-Lb-Id
X-ServedByHost
X-Fastly-Backend-Reqs
CountryCode
X-NodeID
My-App
X-Wp-Cf-Super-Cache
X-Ig-Push-State
X-Lb-Nocache
Location
Server-Info
X-Wp-Cf-Super-Cache-Cache-Control
X-Litespeed-Cache-Control
Wpo-Cache-Status
Ms-Author-Via
X-VCL-Version
Wpo-Cache-Message
Xkeylog
X-Cdn-Request-ID
X-Proxy-Cache-La3
Xkey-La3
Odigeo-Trace-Id
X-MiniProfiler-Ids
X-MSEdge-Flight
X-MSEdge-Features
X-Snapshot-Date
X-Internal-Host
CF-Ctrl
CF-Cached-On
X-Akamai-Pragma-Client-IP
X-Vgn-Hpd-Reason
X-Custom-Header
X-Acquia-Site
X-Acquia-Purge-Tags
OriginIP
Time
Memory
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Acquia-Application-Trace
Memcached
X-Acquia-Application-UUID
Section-Io-Origin-Time-Seconds
X-FL-EDGE
X-Nitro-Rev
Srvid
X-Nitro-Cache-From
Section-Io-Origin-Status
Section-Origin-Responded
FSS-Cache
X-Nitro-Cache
X-FL-QIT-DEBUG
X-APP-VERSION
Ngx
Geoip-Latitude
X-App
X-Shopid
X-Cache-Version
X-Shardid
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Ha-Backend
Akamai-Cache-Status
X-Http-Count
X-Depends
X-PHP-Backend
X-Http-Duration-Ms
X-Te-Count
X-Cache-FS-Status
X-Te-Duration-Ms
X-Via-PopH
X-Dw-Trace-Id
Sm-Log-Id
X-Check-Cacheable
X-Serial
X-Sucuri-Id
X-Th-Server
X-RequestId
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Service-Response-Time
X-Web-Server
X-Via-PopV
X-Mg-Cache
X-Fastly-Cache-Hits
X-Pad
X-Lsadc-Cache
X-Udemy-Cache-App-Namespace
X-Via-PopN