Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-Served-By
X-UA-Compatible
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
P3p
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
X-Ua-Compatible
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Allow
Cf-Edge-Cache
X-Backend
Request-Context
X-UA-Device
Keep-Alive
X-Robots-Tag
X-Cache-Group
X-Server
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-WebKit-CSP
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
Accept-Ch-Lifetime
X-Cache-Lookup
X-Litespeed-Cache
X-Application-Context
X-Country-Code
X-Trace
Content-Location
X-Ruxit-JS-Agent
X-Oneagent-Js-Injection
X-Country
Service-Worker-Allowed
X-Content-Type
X-Clacks-Overhead
X-Url
X-Origin-Cache-Key
X-Edge
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-ECACHE
Cross-Origin-Opener-Policy
X-Mcache
X-Midtier
Cache-Tag
X-Mod-Pagespeed
X-FTR-Request-ID
Accept-Ch
Nginx-Cache
X-MS-InvokeApp
X-PC
X-Vname
X-TtlSet
X-Upstream
X-Powered-By-Plesk
Rating
X-ESI
Edge-Control
X-Server-Name
X-Browser-Type
X-D2id
X-Element-Page-Cache
X-Times
Verso
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Revision
X-Cnection
X-Ac
SPIisLatency
SPRequestDuration
AR-PoweredBy
AR-Request-ID
X-B3-TraceId
AR-SID
AR-ATIME
X-Ruxit-Js-Agent
X-Abt-Application-Version
X-Navigation-Version
SPRequestGuid
X-SharePointHealthScore
X-Vcap-Request-Id
X-NF-Request-ID
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-Ser
X-RateLimit-Remaining
AR-CACHE
X-NWS-LOG-UUID
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-VARITI-CCR
X-Mg-S
S
Pagespeed
X-Middleton-Display
Display
X-Sol
X-Cache-Key
RTSS
Edge-Cache-Tag
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Client-IP
X-Ttl
X-Cache-TTL
X-Powered-CMS
X-Goog-Hash
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Edge-Location-Klb
Cache-Status
X-Kinsta-Cache
X-Version
Access-Control-Request-Method
X-Server-ID
X-Recruiting
Origin-Trial
X-Varnish-TTL
X-ARC
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Content-Security-Policy-Report-Only
X-Content-Digest
X-TraceId
Response
X-Middleton-Response
Arr-Disable-Session-Affinity
X-Forwarded-For
X-Webkit-Csp
X-T
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
X-Accel-Expires
TP-Cache
MicrosoftSharePointTeamServices
X-Hits
X-Shield-Request-Id
X-Cached
X-Daa-Tunnel
Public-Key-Pins
X-Id
Cross-Origin-Resource-Policy
MS-Author-Via
Front-End-Https
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Expires
Server-Node
X-HS-Combine-CSS
X-Ua-Browser
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Request-Processing-Time
X-FastCGI-Cache
X-DIS-Request-ID
X-Request-Received
Payment
X-Frontend
X-Forwarded-Proto
X-LLID
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-RateLimit-Limit
X-GUploader-UploadID
TP-L2-Cache
Realpath
X-Protected-By
X-LB-Cache
X-Fastcgi-Cache
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-Distributor
X-ORACLE-DMS-RID
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
X-Page-Id
X-Az
X-Hostname
X-Activity-Id
X-AppVersion
X-TTL
MRF-Tech
Mrf-Cache-Status
X-Cluster-Name
X-F-Cache
X-B3-TraceId-Primal
X-Kong-Proxy-Latency
Referer-Policy
X-Kong-Upstream-Latency
X-Debug-Info
X-Varnish-Backend
X-Www-Served-By
X-Geo-Country
X-Correlation-Id
X-NGENIX-Cache
Accept-Charset
Fastcgi-Cache
X-PressLabs-Stats
Host
X-App-Server
X-Envoy-Decorator-Operation
X-Varnish-Server
X-WebKit-CSP-Report-Only
X-Goog-Metageneration
X-Ua-Device
X-ORACLE-DMS-ECID
X-FB-Debug
X-Ratelimit-Limit
X-XRDS-LOCATION
Access-Control-Allow-Method
X-Git-Hash
X-RateLimit-Reset
X-Kinja-CCPA
Retry-After
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Fastly-Request-Id
X-Upgrade-Enabled
X-Load-Cache
X-Content-Options
X-Oracle-Dms-Ecid
Server-Name
X-Rid
X-Ezoic-Cdn
X-Px
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Contextid
X-Request-Guid
X-Revision
X-Seen-By
TCN
Charset
X-Datadog-Trace-Id
DC
X-Varnish-Ttl
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Cache-Control
X-Trace-Id
X-CSRF-Token
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
X-Grace
X-Type
Section-Io-Cache
Cleartype
X-App-Environment
X-B-Cache
X-Signature
X-B3-Sampled
X-B
X-TT
Healthy
X-Fb-Rlafr
X-Whom
X-Mobile
X-Wix-Request-Id
X-Oracle-Dms-Rid
X-ASPNET-VERSION
X-Origin-Cache
X-Node-Name
X-EdgeConnect-Cache-Status
Frame-Options
X-Amz-Replication-Status
X-Route-Name
X-Aspnet-Duration-Ms
X-Flags
X-Providence-Cookie
X-Is-Crawler
X-Newrelic-App-Data
X-Magnolia-Registration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Logged-In
X-Language
X-Azure-Ref
Filterid
X-Proxy
X-N
X-Fastly-Request-ID
X-Air-Pt
X-Ratelimit-Remaining
Content-Disposition
Akamai-GRN
Backend
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Upgrade-Insecure-Requests
X-Template
X-App-Version
X-Original-Request-Id
NGB
X-Response-Served-From
Refresh
X-Proxy-Cache-Info
SD-X-WS
X-Is-Bot
X-Rendered-As
X-ProcessESI
X-Tumblr-Pixel-1
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-RemovedCookies
X-Unique-Id
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Varnish-Grace
X-Datadog-Sampled
MS-CV
X-RTag
X-Instance
Ms-Operation-Id
X-Servername
Liferay-Portal
X-Amzn-Remapped-Content-Length
Viewport
X-FW-Static
X-FW-Server
X-FW-Hash
X-FW-Dynamic
X-FW-Type
X-FW-Version
X-UUID
X-IPS-LoggedIn
X-Debug-IsPreview
X-Debug-IsConnected
X-Debug
X-FW-Serve
Fastly-SWR
X-Cache-Grace
X-Region
X-Cacheable-TTL
Fastly-SIE
X-User-Agent
X-Adobe-Loc
X-Adobe-Content
X-G
X-Device-Type
X-Time
X-NYM-Debug-Backend
X-Rule
From-Origin
X-Environment-Context
Country
X-Backend-Name
X-Cache-Hit
X-L-Path
X-Hl-Ver
Url
X-Status
ServerID
X-Jobs
X-B3-SpanId
X-Page-View
X-Cache-Age
X-CCDN-CacheTTL
Countrycode
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Via-JSL
Surrogate-Key
X-Origin-CC
X-Origin-TTL
X-VC-Cache
Amp-Access-Control-Allow-Source-Origin
X-Air-Source
X-Hosted-By
X-INCAP-ABP
X-Air-Trace-Id
X-Air-Hostname
X-Webkit-CSP
WPO-Cache-Message
Alternate-Protocol
WPO-Cache-Status
X-Cache-Status-Check
Version
X-HTML-Minification-Powered-By
X-Akamai-Request-ID2
X-Content-Powered-By
X-NODE
Protected
GEO-INFO
CDN-RequestId
X-Akamai-Edgescape
X-Rocket-Nginx-Serving-Static
X-Nginx-Cache
X-Source
SRV
X-Storage
X-WP-CF-Super-Cache-Active
X-Http-Reason
X-B3-Traceid
X-Accel-Version
X-Framework
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Edge-Location
Access-Control-Request-Headers
CF-IPCountry
Front
X-CDN-Forward
X-Real-IP
X-Cache-Rule
OT-Force-Account-Verify
X-Mode
X-VC
X-Upstream-Ht
X-Rn-Rsrv
X-Httpd
X-XRDS-Location
Accept-Language
X-Cache-Operation
Meta-Geo
X-UPSTREAM-Address
Filters
Webserver
X-Xfnlog-Site
X-Upstream-Ct
X-Rewrite-Enabled
Xet-Cookie
X-Soup
X-Timing-Wait
Selected-Fe
X-Director
X-Proxy-Build
X-Endurance-Cache-Level
X-Served-From
X-JoinUs
X-SaId
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Worker
X-Cache-Time
X-Handled-By
X-Logging-Id
X-Use-Mantle
X-Detected-As
X-Web-Node
X-Origin
X-Say-TTL
ServedBy
X-Say-Cacheable
X-Redis-Cache
X-SayCDN-TTL
X-Cache-Debug
X-Varnish-Cache-Hits
TWC-Connection-Speed
Azure-Version
Azure-SlotName
Azure-InstanceId
Azure-SiteName
DB-Nickname
Azure-RegionName
X-Restarts
X-Lambda-Id
X-Loop
X-ProxyCache-Status
X-GeoCountry
X-Format
X-GeoCode
X-ProxyCache-Key
X-Adobe-Source
X-Varnish-Age
X-VCT
X-No-Session
Xserver
X-Origin-Hint
X-Cms-Context
X-Tncms
Web-Mar-Node
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-RM-Cache-TTL
Webcakes-App-Version
X-PHP-Host
X-Labrador-Cache-Channel
X-BYPASS-REASON
X-Server-W
Webcakes-Region
TWC-Device-Class
Property-Id
X-ServerID
X-Git-Commit
X-Varnish-Beresp-Grace
X-Skip-Cache
Mn-Server-Ip
X-IPLB-Instance
X-Generation-Time
X-Fetched-On
X-Cache-Server
Section-Io-Id
X-Container-Uri
X-DynaTrace
X-AWS-Id
Apigw-Requestid
X-IPLB-Request-ID
Cross-Origin-Embedder-Policy
X-LJ-Flow-ID
X-Vercel-Id
X-VWS-Id
X-RCS-CacheZone
X-Vercel-Cache
X-Tb
X-Cluster
X-Site-Version
X-Reqid
X-Provided-By
X-Vcache
X-Cache-Host
X-Frame-Option
Node
X-Locale
X-Is-Supported-Browser
X-Platform-Processor
X-Extlb
X-Is-Mobile
X-Platform-Router
X-Is-Tablet
X-S
X-Ms-Version
X-Ms-Request-Id
X-Platform-Cluster
X-Proxied
X-Zipkin-Id
X-AB
AMP-Access-Control-Allow-Source-Origin
X-Forwarded-Host
X-Uri
X-Browser-Name
X-Routing-Service
X-Is-Desktop
X-Geo-Region
X-Tcp-Rtt
X-R9-Blue-Green-Version
X-Webstats-RespID
X-Drupal-Cache-Tags
X-TT-LOGID
X-Sql-Count
X-Drupal-Cache-Contexts
X-Sql-Duration-Ms
Cache-Tv-Group
X-MP-GENERATED-AT
X-Origin-Date
Source
Fastcgi-Useragent
WP-Super-Cache
CDN-PullZone
CDN-RequestPullSuccess
CDN-RequestCountryCode
X-FB-TRIP-ID
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-Uid
X-Vcl-Version
Content-Secure-Policy
Priority
X-Sucuri-Cache
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Generated-By
X-Use-Magma
X-Sucuri-ID
Onion-Location
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Cdn-Origin
Locale
X-Content-Age
X-SRV
X-Xrds-Location
Sid
Cross-Origin-Embedder-Policy-Report-Only
X-Pass-Why
S-Rt
WZWS-RAY
X-Cluster-Node
X-Buckets
X-Newrelic-Synthetics
X-DataDome
X-Thinkindot-L3
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
TDXMobile
X-Scope-Id
X-Shield-Cache-Expires
X-CMSURLCustom
Cross-Origin-Window-Policy
X-Proxy-Cache-Status
X-Varnish-Beresp-Ttl
Atl-Traceid
X-Cache-Action
X-LSADC-Cache
Cache
X-Ua
X-Cache-Expired-At
X-GEO
X-COUNTRY
X-WP-CF-Super-Cache-Cookies-Bypass
X-Via-Edge
X-Via-SSL
Edge-Copy-Time
X-Via-CDN
X-Ec-Custom-Error
X-A-Dcw
Type
X-Ec-Fail
X-A-Dgt
X-Vtex-Remote-Cache
X-Developer
X-Destination
X-A-Ccd
X-A
Fastly-Drupal-HTML
X-Rojux
X-PAYTM-SRV-ID
X-A-Dam
X-Viewer-Country
Gannett-Cam-Experience-Id
Origin-Agent-Cluster
Redirect-Candidate
DCR-Processing-Time-Ms
DCR-Decision-By
Origin
Lang
Meta-Geo-Continent
MD5-Digest
Ngx-Var-Key
Ngx.Var.Host
Rendered-Blocks
CDCHOST
X-Vdms-Path
X-Optimistic-Header
X-A-Wwc
X-Epic-Correlation-Id
X-Vdms-Version
X-External-Request-Id
Candidate-Md5Url
Sslversion
Surrogated-Key
T-Server
X-Ec-GeoHdr
X-S-Cookie
HostName
X-Scheme
X-TIM-N
X-B-Cookie
X-Application
X-BCube-Filmed-By
X-SRCache-Key
X-Conf
X-Request-URI
X-Cache-NE
X-Cache-Bucket
X-Bl-Debug
X-D
X-Bc-Bl
X-ScT
X-Aed
X-Aspnetmvc-Version
X-Mg-Request-UUID
X-Varnish-Hostname
X-GeoIP-Region-Code
X-Cache-Info
X-Bip
Apple-News-Services-Handled
Pramga
Apple-News-Services-Host
X-Nyt-Route
X-Sigma-Backend
X-Varnishpool
X-Request-Start
X-Op-Id-All
Apple-News-Services-Parsed-Url
X-Platform
X-Node-Id
Apple-News-Services-Request-Url
X-Level-Front-Cache
X-Loc
X-Fastly-Cache
Environment
X-Instance-Name
X-Human
Cluster
Release
Fastly-GeoIP-CountryCode
Ssr
X-Correlation-ID
Fastly-SSL
Sever-Int
Server-Ext
Server-Hostname
DSUID
X-Varnish-Director
X-VG-WebCache
X-SB
X-VServer
X-Gdpr
X-Generated-On
X-Request-Time
X-Rocket-Build-Number
X-Section
X-Debug-Cache-Store
X-Clientip
X-Forwarded-Site
X-SD-PageType
X-We-Are-Hiring
Magicmarker
X-TH-Server
L
X-Debug-Cache-Fetch
X-Dispatcher-Server
X-Sigma
Vix-Hermes-Req-Id
X-Origin-Time
Server-Host
X-Varnish-Beresp-Status
Req-ID
X-GeoIP-Country-Code
X-Thanos
X-Access
V-Age
X-Pubstack
X-Proxied-Request
X-Pool
Host-ID
X-VCache
X-Connection-Hash
X-Origin-Response-Time
X-Datadome
Expiry
User-Cache-Control
X-TimeS
X-Contensis-Viewer-Groups
Wxu-Next-Region
On-Server
Wxu-Next-Hostname
Wxu-Next-Commit
We-Hiring
X-Auto-Login
X-ApacheServer
Web-Mar-Region
X-B3-Trace-ID
X-Cache-Date
X-Cache-Aspx
X-FC-Vary-Parameters
Req-Svc-Chain
X-Block-Status
X-Acquia-Purge-Cdn-Unconfigured
Uber-Trace-Id
X-BBC-Edge-Cache-Status
True-Client-Country-4JS
X-Device-Os
X-NCache
X-Request-Host
X-Req
X-Var-Ttl
X-Gen-Mode
Content-Script-Type
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-PERF
X-Policy
X-UA-Device-Type
NM-Fastcgi-Cache
A
X-WA-Info
X-Gzip
X-Cache-Id
X-Esi-Check
X-SVT-ORM-RULES
X-Branch-Name
X-Mly-Id
X-VG-TLSProxy
Content-Style-Type
X-SVT-ORM-VERSION
X-NMSegId
X-Org
X-Varnish-Authentication
X-Server-IP
X-GoCache-CacheStatus
X-Hnp-Log
X-HS-Content-Campaign-Id
X-V-Cache
Gh-Request-Id
X-GeoIP-City
Mail-Subject
Machine
X-Geo-Header
X-GeoIP
X-Irp-Debug
X-Men
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-TA-CDN-Provider
X-Nginx-Cache-Key
C-Via
X-Moov-Xdn-Version
X-Zen-Fury
Canary
X-Moov-T
Cache-Provider
X-Core-Value
X-Service
X-Wikidot-Static-Cache
Producers
Platform
X-Test
Esi-Enabled
Adler-Geo
Is-Eu
X-Cache-TTL-Remaining
X-Proto
X-Amz-Meta-Cb-Modifiedtime
X-Fastly-Backend
X-Fmm-Version
X-Hash
X-Cdn-Srv
X-Old-Content-Length
X-Wikidot-Backend
X-Up
X-DPWN-IS-SECURE
X-From
X-Micro-Cache
X-Ad-Load-Variation
X-App-Name
Tube-Return
AKAMAI
Click-Count-Error
W
Tube-Got-Results
Tube-Got-Eval
Country-Code
X-DC
X-Dc
X-Aicache-OS
Tube-Get-Contents
Click-Count-Action-Start
Cache-Key
X-Parent-Response-Time
Locid
Cdnsip
Cdn-Host
X-Sn-Servicetimems
L5d-Success-Class
HA-Ipaddr
X-ND-Cache
X-Region-Sid
Fastly-Backend-Name
RNT-Time
X-Slack-Shared-Secret-Outcome
Ha-Gx-Prefs
RNT-Machine
Cdn-Request-Time
Yak-Timeinfo
X-CacheTTL
X-Csrf-Jwt
X-AK-Request-ID
Proxy-Firewall
Cf-Device-Type
Cdncip
X-CGP
X-Slack-Backend
X-Edge-Server
X-Eu-Site
Pics-Label
X-Owner
X-Accel-Expires-Debug
X-Tx-Id
NGX
X-Ah-Environment
X-SIPLIST1
X-Qloud-Router
PFcat
X-Date
Datacenter
X-Azure-Ref-OriginShield
X-Amz-Storage-Class
X-Core-Mission
X-HN
IsBot
X-VarnishDD-TTL
X-ZONE
X-Via-Poph
X-LB-ID
X-Via-Popn
X-HA-Backend
X-Via-Popv
LB
X-Backend-Instance
X-URL
X-CF-Lambda-Version
N-Cache
X-CF-Lambda-Fn
X-Refresh
Cdn
X-Servedbyhost
X-CACHE-GROUP
X-Tb-Optimization-Total-Bytes-Saved
XM
Expect-Staple
X-LB-NoCache
X-Ratelimit-Reset
X-Shop-Environment
X-CDN-Cache-Status
X-Cache-Backend
X-NGINX-Cache
X-Cache-Type
X-Tenant
NtCoent-Length
X-Origin-Expires
Xc-Version
X-Forwarded-Path
X-Varnish-Hits
GeoIp-Country-Code
X-Orig-Expires
X-DynaTrace-JS-Agent
X-API-Version
X-VHOST
X-Client-Ip
X-Lagoon
X-Nc
SID
RATING
X-Gamma-Serve
X-Wa
Cdn-Requestid
X-ECache
Cmstype
Cmsid
CloudFront-Viewer-Country
CPC-Age
CPC-Cache
X-Srv
Server-ID
X-UA
X-Nananana
Resin-Trace
X-Vmg-Version
X-Cdn-Diag
X-Zone
X-Akamai-Transformed
X-Tt-Logid
Cross-Origin-Opener-Policy-Report-Only
X-TX-ID
X-Via-Fastly
X-Fpc
X-Hit
Uri
X-LAGOON
X-TIME
X-Proxy-CacheRZ
XkeyRZ
GeoIP-Latitude
User-Agent
X-B3-Parentspanid
X-Nf-Request-Id
CacheControlHeader
Cache-Hits
X-CACHE-AGE
X-Api-Version
X-RID
X-Location
X-Presslabs-Stats
X-Variation
X-Ig-Origin-Region
X-NewRelic-App-Data
X-Info
Fusion-Content-Id
Fusion-Source
X-Fastly-Country-Code
Fusion-Component-Id
Fusion-Template-Id
Fusion-Deployment-Id
DataCenter
Fusion-Content-Source
X-DataCenter
X-Amz-Meta-Opti
MIME-Version
True-Client-IP
Tcn
X-CS
Lb
X-Cloudmap
True-Client-Ip
X-Esi
Powered-By
VNS-Cache
VNS-Age
X-Datacenter
X-NWS-UUID-VERIFY
X-CSRF-TOKEN
X-B3-Spanid
X-Dynatrace-Js-Agent
X-HostName
X-CUA
Hostname
Mime-Version
Origin-CC
X-Vc
Origin-EX
X-Jungle-Id
X-LiteSpeed-Tag
Fastly-Drupal-Html
X-Geo
X-User
X-Cached-By
Cf-Ipcountry
X-LiteSpeed-Cache-Control
X-IAuth-Set-Uid
Cache-Name
X-Cdn-Forward
X-Segment-20210421
X-HOST
Debug
Srv
Load-Balancing
X-Varnish-Beresp-TTL
X-Dispatcher-Number
X-AIR-PT
Cl-Cache
X-Render-Time
X-Webkit-Csp-Report-Only
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Server
X-VTEX-Cache-Time
CDN
X-FPC
X-Mid
X-Auth-Group-Type
X-MCACHE
Edge-Cache
X-Dispatch
Server-Id
GeoIP-Country-Code
X-Wormhole-Sdk
Ohc-File-Size
X-Litespeed-Tag
X-Oracle-DMS-ECID
X-Ig-Push-State
X-WA
X-Cdn-Cache-Status
X-NC
BehaviorPad-Version
Ohc-Cache-HIT
X-NodeID
X-ServedByHost
Odigeo-Trace-Id
X-Lb-Nocache
X-APP-VERSION
X-Cs
X-Cache-Ttl
X-Fastly-Backend-Reqs
X-Vgn-Hpd-Reason
X-Custom-Header
X-Lb-Id
X-Cache-Enabled
CountryCode
YJS-ID
X-Litespeed-Cache-Control
X-VCL-Version
Ms-Author-Via
Xkey-La3
X-MiniProfiler-Ids
X-PHP-Backend
Xkeylog
X-Snapshot-Date
X-Depends
X-Via-PopH
Server-Info
X-Via-PopV
X-Via-PopN
X-Proxy-Cache-La3
X-Ha-Backend
X-Cdn-Request-ID
Location
X-MSEdge-Flight
My-App
X-MSEdge-Features
X-Akamai-Pragma-Client-IP
X-Pad
X-Acquia-Application-Trace
Memory
Time
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Acquia-Application-UUID
X-Acquia-Site
X-Acquia-Purge-Tags
Memcached
Srvid
X-FL-QIT-DEBUG
X-IN-APIGATEWAYSSL
Ngx
X-DefHash
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Internal-Host
CF-Ctrl
X-DefElseHash
X-Varnish-CookieHashed-On
X-IN-APIGATEWAY
X-FL-EDGE
FSS-Cache
CF-Cached-On
OriginIP
X-Shopid
X-Shardid
Wpo-Cache-Status
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Cache-Version
Wpo-Cache-Message
X-M-Reqid
X-M-Log
PICS-Label
Akamai-Cache-Status
Warning
X-Web-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
Geoip-Latitude
X-RequestId
X-Udemy-Cache-App-Namespace
X-Th-Server
X-Sucuri-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Lsadc-Cache
X-App
X-Nitro-Cache
X-Service-Response-Time
Section-Io-Origin-Status
X-Dw-Trace-Id
X-Mg-Cache
X-Serial
X-Check-Cacheable
X-Nitro-Cache-From
X-Nitro-Rev
Sm-Log-Id
X-Fastly-Cache-Hits