Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-Served-By
X-UA-Compatible
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-AspNet-Version
X-Runtime
X-DNS-Prefetch-Control
Accept-CH
X-Ua-Compatible
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
X-Dns-Prefetch-Control
Cf-Apo-Via
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-CST
X-WebKit-CSP
X-Backend-Server
X-OneAgent-JS-Injection
Permissions-Policy
Accept-Ch-Lifetime
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Cache-Lookup
X-Oneagent-Js-Injection
X-Litespeed-Cache
X-Trace
Content-Location
X-Ruxit-JS-Agent
Service-Worker-Allowed
X-Url
X-Content-Type
X-Country
X-Clacks-Overhead
X-ECACHE
X-Edge
X-Origin-Cache-Key
X-Mcache
Accept-Ch
X-Mod-Pagespeed
X-Amz-Server-Side-Encryption
X-Midtier
Cross-Origin-Opener-Policy
X-Rack-Cache
X-FTR-Request-ID
Cache-Tag
X-MS-InvokeApp
Nginx-Cache
X-Upstream
X-ESI
X-TtlSet
X-PC
X-Vname
X-Powered-By-Plesk
Rating
Edge-Control
X-Browser-Type
X-D2id
Verso
X-Element-Page-Cache
X-Server-Name
X-Times
X-Exp-Id
X-Cnection
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-Ruxit-Js-Agent
SPRequestDuration
X-Ac
SPIisLatency
X-B3-TraceId
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
SPRequestGuid
X-SharePointHealthScore
X-Navigation-Version
X-Vcap-Request-Id
X-RateLimit-Remaining
X-NF-Request-ID
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-GitHub-Request-Id
X-Ser
X-VARITI-CCR
AR-CACHE
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
S
X-Mg-S
X-Cache-Key
Pagespeed
X-Sol
X-Middleton-Display
Display
X-NWS-LOG-UUID
Edge-Cache-Tag
X-Client-IP
X-Cache-TTL
X-Amzn-Trace-Id
Fastly-Restarts
X-Amz-Rid
RTSS
X-Powered-CMS
Origin-Trial
X-Goog-Hash
X-Ttl
X-Varnish-TTL
X-Kraken-Loop-Name
X-Version
X-Server-ID
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
X-Server-Lifecycle-Phase
X-Edge-Location-Klb
X-Kinsta-Cache
Cache-Status
Access-Control-Request-Method
X-Content-Security-Policy-Report-Only
X-Recruiting
X-ARC
X-Webkit-Csp
X-TraceId
X-Content-Digest
Arr-Disable-Session-Affinity
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-T
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
X-Middleton-Response
X-Forwarded-For
Response
X-Ua-Device
Content-MD5
MicrosoftSharePointTeamServices
X-Accel-Expires
TP-Cache
X-Shield-Request-Id
X-RateLimit-Limit
X-Cached
X-Hits
X-Id
X-Fastcgi-Cache
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
Public-Key-Pins
Server-Node
MS-Author-Via
X-FTR-Expires
X-Request-Received
X-Request-Processing-Time
X-Ua-Browser
X-HS-Content-Id
X-HS-Combine-CSS
Front-End-Https
X-HS-Hub-Id
Payment
X-HS-Cache-Config
Cross-Origin-Resource-Policy
X-Frontend
X-DIS-Request-ID
X-Forwarded-Proto
X-Daa-Tunnel
X-LLID
X-HP-Trace-Id
X-GUploader-UploadID
X-HP-Webp
X-Jurisdiction
X-LB-Cache
Realpath
TP-L2-Cache
X-Protected-By
Cache-Tags
X-Amzn-RequestId
X-Amz-Apigw-Id
X-WebKit-CSP-Report-Only
X-Origin-Server
X-Distributor
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
X-TTL
X-FastCGI-Cache
X-Page-Id
X-ORACLE-DMS-RID
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Www-Served-By
X-AppVersion
X-NGENIX-Cache
X-Activity-Id
X-F-Cache
X-Kinja-CCPA
X-Az
X-Cluster-Name
Referer-Policy
X-Hostname
Accept-Charset
X-Varnish-Backend
X-Geo-Country
X-Debug-Info
X-Correlation-Id
X-Envoy-Decorator-Operation
X-App-Server
Fastcgi-Cache
X-Varnish-Server
X-PressLabs-Stats
Host
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Goog-Metageneration
X-FB-Debug
Access-Control-Allow-Method
X-Rid
X-Git-Hash
X-ORACLE-DMS-ECID
X-RateLimit-Reset
Retry-After
X-Oracle-Dms-Ecid
X-XRDS-LOCATION
Server-Name
X-CSRF-Token
X-Content-Options
X-Load-Cache
X-Upgrade-Enabled
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Px
X-Flags
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Contextid
X-Is-Crawler
X-Aspnet-Duration-Ms
DC
X-Revision
X-Trace-Id
X-Cache-Control
X-App-Environment
TCN
Charset
Paypal-Debug-Id
X-Origin-Cache
X-B-Cache
X-Type
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-B
X-Signature
X-Grace
Cleartype
X-Ezoic-Cdn
X-TT
X-Oracle-Dms-Rid
Section-Io-Cache
X-B3-Sampled
X-ASPNET-VERSION
X-Seen-By
X-Amz-Meta-S3cmd-Attrs
X-Mobile
X-Fastly-Request-ID
X-Ratelimit-Limit
X-Fb-Rlafr
Healthy
Frame-Options
X-Amz-Replication-Status
X-Magnolia-Registration
X-Whom
X-Language
X-Wix-Request-Id
X-Logged-In
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Node-Name
X-Goog-Generation
X-Fastly-Request-Id
Filterid
X-EdgeConnect-Cache-Status
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Azure-Ref
X-App-Version
X-Proxy
X-Newrelic-App-Data
X-N
Content-Disposition
Backend
X-Varnish-Ttl
Akamai-GRN
X-Template
X-Air-Pt
Refresh
Upgrade-Insecure-Requests
NGB
X-Proxy-Cache-Info
X-Response-Served-From
X-Original-Request-Id
X-Is-Bot
X-Rendered-As
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel-0
X-Tumblr-Pixel
SD-X-WS
X-Tumblr-Pixel-1
VIX-Pulpo-Node
X-Tumblr-User
X-Unique-Id
X-RemovedCookies
X-ProcessESI
X-Page-View
Viewport
Liferay-Portal
X-Adobe-Content
X-Debug-IsConnected
X-Debug-IsPreview
Ms-Operation-Id
X-Adobe-Loc
X-Instance
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Servername
X-Datadog-Sampled
X-UUID
X-Varnish-Grace
MS-CV
X-Amzn-Remapped-Content-Length
X-RTag
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-IPS-LoggedIn
X-G
X-Ratelimit-Remaining
X-Debug
X-FW-Type
X-FW-Version
Fastly-SWR
X-Region
X-User-Agent
X-FW-Static
Fastly-SIE
X-FW-Server
X-Cacheable-TTL
X-Cache-Grace
X-FW-Hash
X-FW-Dynamic
Url
X-FW-Serve
X-Rule
X-Device-Type
X-NYM-Debug-Backend
From-Origin
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Environment-Context
X-L-Path
X-Cache-Hit
X-Jobs
Country
X-Hl-Ver
X-Backend-Name
X-Status
X-B3-SpanId
ServerID
Surrogate-Key
X-Webkit-CSP
X-Cache-Age
Countrycode
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Hosted-By
X-Time
X-Content-Powered-By
X-Origin-CC
X-Origin-TTL
Alternate-Protocol
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-VC-Cache
X-Akamai-Request-ID2
X-NODE
X-Http-Reason
X-Cache-Status-Check
Amp-Access-Control-Allow-Source-Origin
Protected
X-INCAP-ABP
X-HTML-Minification-Powered-By
X-Via-JSL
WPO-Cache-Status
X-B3-Traceid
WPO-Cache-Message
Version
SRV
X-Akamai-Edgescape
X-Rocket-Nginx-Serving-Static
X-CDN-Forward
X-Nginx-Cache
GEO-INFO
CF-IPCountry
X-Framework
X-Storage
X-Edge-Location
X-Accel-Version
X-Source
X-WP-CF-Super-Cache-Active
X-Cache-Rule
Access-Control-Request-Headers
Front
X-XRDS-Location
CDN-RequestId
X-Httpd
X-Use-Magma
X-Use-Mantle
OT-Force-Account-Verify
X-Mode
X-Real-IP
X-Rewrite-Enabled
X-Xfnlog-Site
X-Upstream-Ct
Accept-Language
X-Upstream-Ht
X-VC
Filters
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-Rn-Rsrv
X-Cache-Operation
Meta-Geo
Webserver
X-SaId
X-Proxy-Build
X-Detected-As
X-JoinUs
X-Director
X-Served-From
X-Cache-Debug
X-Timing-Wait
X-Soup
Selected-Fe
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Sql-Count
X-Sql-Duration-Ms
X-Cms-Context
X-ProxyCache-Status
X-BYPASS-REASON
X-Adobe-Source
X-Handled-By
X-Redis-Cache
X-Varnish-Cache-Hits
X-Origin
X-Logging-Id
ServedBy
X-ProxyCache-Key
DB-Nickname
TWC-GeoIP-Country
Azure-RegionName
X-Loop
TWC-GeoIP-LatLong
X-S
Azure-SiteName
X-Restarts
Azure-Version
Azure-SlotName
TWC-Locale-Group
TWC-Privacy
X-Origin-Hint
Webcakes-App-Name
TWC-Device-Class
Webcakes-App-Version
Webcakes-Region
X-Cache-Time
Azure-InstanceId
X-Lambda-Id
Web-Mar-Node
X-Format
Property-Id
TWC-Connection-Speed
X-Varnish-Age
X-Say-Cacheable
X-Worker
X-VCT
X-Tncms
Xet-Cookie
X-Server-W
AMP-Access-Control-Allow-Source-Origin
X-Say-TTL
X-SayCDN-TTL
X-No-Session
Xserver
X-IPLB-Instance
X-Git-Commit
Mn-Server-Ip
X-DynaTrace
X-Cache-Server
X-AWS-Id
X-Container-Uri
X-IPLB-Request-ID
X-RCS-CacheZone
X-Fetched-On
X-Generation-Time
X-VWS-Id
X-RM-Cache-TTL
X-Tb
X-Labrador-Cache-Channel
Apigw-Requestid
X-Varnish-Beresp-Grace
X-Skip-Cache
X-LJ-Flow-ID
X-Vercel-Cache
X-PHP-Host
X-Vercel-Id
X-Browser-Name
X-Ms-Version
X-Cache-Host
X-Is-Tablet
X-Geo-Region
X-Is-Desktop
X-Is-Mobile
X-Provided-By
X-Frame-Option
X-Is-Supported-Browser
X-Cluster
X-AB
X-Reqid
X-Ms-Request-Id
Section-Io-Id
X-ServerID
Node
X-Tcp-Rtt
X-GeoCode
X-Zipkin-Id
X-Web-Node
X-Extlb
X-GeoCountry
X-Proxied
X-Locale
X-R9-Blue-Green-Version
X-Routing-Service
X-Site-Version
X-Forwarded-Host
Cross-Origin-Embedder-Policy
X-Platform-Router
X-Uri
X-Platform-Cluster
X-Platform-Processor
Cache-Tv-Group
X-Webstats-RespID
X-COUNTRY
X-FB-TRIP-ID
Source
X-Drupal-Cache-Contexts
Priority
X-Drupal-Cache-Tags
X-Vcache
X-MP-GENERATED-AT
Fastcgi-Useragent
Content-Secure-Policy
X-Origin-Date
X-Vcl-Version
CDN-Uid
CDN-RequestPullCode
CDN-CachedAt
CDN-Cache
CDN-EdgeStorageId
CDN-PullZone
WP-Super-Cache
CDN-RequestCountryCode
CDN-RequestPullSuccess
X-Alternate-Cache-Key
Onion-Location
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Urbn-Site-Id
WZWS-RAY
X-Urbn-Context-Path
Locale
X-Content-Age
X-Xrds-Location
X-Sorting-Hat-PodId
X-Pass-Why
S-Rt
X-Sucuri-Cache
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-Generated-By
X-Newrelic-Synthetics
X-Cdn-Origin
X-TT-LOGID
X-Sucuri-ID
Sid
X-Varnish-Beresp-Ttl
X-Ua
X-SRV
X-Cluster-Node
X-Buckets
X-Proxy-Cache-Status
Cross-Origin-Embedder-Policy-Report-Only
X-Cache-Action
X-Cache-Expired-At
X-VCache
Cross-Origin-Window-Policy
TDXMobile
X-CMSURLCustom
X-Scope-Id
X-Shield-Cache-Expires
X-Thinkindot-L3
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-DataDome
X-LSADC-Cache
Cache
X-Mg-Request-UUID
HostName
Atl-Traceid
Fastly-Drupal-HTML
X-Request-URI
X-Aspnetmvc-Version
X-Via-SSL
Edge-Copy-Time
X-Via-Edge
X-Via-CDN
DCR-Decision-By
X-PAYTM-SRV-ID
Gannett-Cam-Experience-Id
Environment
Candidate-Md5Url
X-SRCache-Key
Sslversion
X-Correlation-ID
X-Optimistic-Header
CDCHOST
X-ScT
Meta-Geo-Continent
T-Server
DCR-Processing-Time-Ms
Ngx-Var-Key
Ngx.Var.Host
Origin-Agent-Cluster
X-Rojux
MD5-Digest
X-Scheme
Origin
Redirect-Candidate
X-S-Cookie
Lang
Rendered-Blocks
Surrogated-Key
X-Bc-Bl
X-BCube-Filmed-By
X-Bl-Debug
X-Cache-Bucket
X-Vtex-Remote-Cache
X-B-Cookie
X-Aed
X-Vdms-Version
X-Application
X-Cache-NE
X-External-Request-Id
X-D
X-Destination
X-Developer
X-Ec-Custom-Error
X-Conf
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Ec-Fail
X-Vdms-Path
X-Viewer-Country
X-A-Dgt
X-A-Dam
X-A-Dcw
X-TIM-N
X-A-Wwc
X-A-Ccd
Type
X-A
X-WP-CF-Super-Cache-Cookies-Bypass
X-Datadome
X-GEO
X-TimeS
Fastly-SSL
V-Age
X-Core-Value
X-Clientip
Server-Hostname
X-Generated-On
Server-Host
Sever-Int
X-Loc
X-Debug-Cache-Store
X-Mly-Id
Ssr
DSUID
X-Debug-Cache-Fetch
Fastly-GeoIP-CountryCode
X-Dispatcher-Server
Server-Ext
X-Gdpr
L
Pramga
X-B3-Trace-ID
Apple-News-Services-Parsed-Url
X-BBC-Edge-Cache-Status
X-GeoIP-Region-Code
X-Forwarded-Site
X-Acquia-Purge-Cdn-Unconfigured
Release
Req-ID
X-Aicache-OS
Req-Svc-Chain
X-Bip
X-Access
Host-ID
X-Instance-Name
X-Level-Front-Cache
X-Human
X-Fastly-Cache
X-GeoIP-Country-Code
Vix-Hermes-Req-Id
Magicmarker
X-Cache-Info
Apple-News-Services-Request-Url
X-Nyt-Route
X-Varnish-Director
X-Varnish-Beresp-Status
X-Node-Id
X-Proxied-Request
X-Varnish-Hostname
Apple-News-Services-Host
X-Op-Id-All
X-Req
X-TH-Server
X-Thanos
X-Pool
X-Pubstack
X-Origin-Time
X-Platform
X-Varnishpool
X-Origin-Response-Time
X-Sigma
X-Request-Time
X-VG-TLSProxy
X-Rocket-Build-Number
X-SB
X-Section
X-SD-PageType
X-Sigma-Backend
Apple-News-Services-Handled
X-Request-Start
X-VG-WebCache
X-VServer
X-We-Are-Hiring
X-WA-Info
User-Cache-Control
Tube-Return
X-Geo-Header
Tube-Got-Results
Tube-Got-Eval
X-SVT-ORM-VERSION
X-Gen-Mode
Tube-Get-Contents
X-SVT-ORM-RULES
X-GeoIP-City
X-TA-CDN-Provider
X-Block-Status
X-Fmm-Version
X-Auto-Login
X-ApacheServer
Cluster
X-Cache-Date
X-Esi-Check
X-Cache-TTL-Remaining
X-Cache-Id
X-FC-Vary-Parameters
X-From
X-Var-Ttl
Wxu-Next-Commit
Web-Mar-Region
We-Hiring
X-UA-Device-Type
Wxu-Next-Hostname
Wxu-Next-Region
X-V-Cache
X-Up
X-Server-IP
Uber-Trace-Id
X-GeoIP
X-Old-Content-Length
X-Men
Country-Code
X-Micro-Cache
X-Org
X-PERF
X-Policy
X-Irp-Debug
Gh-Request-Id
X-Mvc-Supplant-Cachable
Click-Count-Error
Cache-Provider
C-Via
X-NMSegId
X-Device-Os
X-Nginx-Cache-Key
Canary
Click-Count-Action-Start
X-Mvc-Supplant-OutputCached
X-NCache
X-HS-Content-Campaign-Id
Esi-Enabled
On-Server
X-Gzip
X-Request-Host
NM-Fastcgi-Cache
X-RateLimit-Remaining-Second
X-Hnp-Log
X-RateLimit-Limit-Second
Mail-Subject
Machine
X-DC
X-Service
X-Connection-Hash
Expiry
AKAMAI
Cdn-Request-Time
X-Zen-Fury
Content-Style-Type
Cdn-Host
X-GoCache-CacheStatus
Platform
X-Moov-Xdn-Version
X-Cdn-Srv
X-Edge-Server
X-Core-Mission
X-Moov-T
Content-Script-Type
Pics-Label
X-Fastly-Backend
X-SIPLIST1
Cf-Device-Type
X-Hash
True-Client-Country-4JS
Producers
Is-Eu
IsBot
X-Proto
W
X-DPWN-IS-SECURE
X-Test
A
X-Branch-Name
X-App-Name
X-ZONE
Adler-Geo
X-Ad-Load-Variation
X-Parent-Response-Time
X-Dc
RNT-Machine
X-Wikidot-Static-Cache
X-Amz-Meta-Cb-Modifiedtime
RNT-Time
X-Sn-Servicetimems
X-Via-Poph
X-Via-Popn
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-HA-Backend
X-Via-Popv
Cache-Key
X-Varnish-Authentication
X-Eu-Site
X-Contensis-Viewer-Groups
X-Cache-Aspx
X-Wikidot-Backend
X-CGP
HA-Ipaddr
X-CacheTTL
L5d-Success-Class
NGX
Proxy-Firewall
Ha-Gx-Prefs
X-Ah-Environment
Fastly-Backend-Name
X-Csrf-Jwt
Datacenter
X-Owner
X-Region-Sid
Locid
N-Cache
Expect-Staple
X-LB-NoCache
X-Accel-Expires-Debug
LB
X-Date
Yak-Timeinfo
X-CF-Lambda-Version
X-ND-Cache
X-CF-Lambda-Fn
X-Shop-Environment
Cdncip
X-Amz-Storage-Class
X-HN
X-Qloud-Router
X-Tenant
X-Cache-Type
PFcat
Xc-Version
X-Forwarded-Path
X-LB-ID
Cdnsip
X-VarnishDD-TTL
X-Orig-Expires
Cdn-Requestid
X-Tt-Logid
X-AK-Request-ID
Cdn
X-Ratelimit-Reset
X-Tb-Optimization-Total-Bytes-Saved
X-NGINX-Cache
X-Varnish-Hits
X-Backend-Instance
X-Refresh
X-Tx-Id
X-Gamma-Serve
X-VHOST
X-Azure-Ref-OriginShield
RATING
X-Servedbyhost
Cmstype
GeoIp-Country-Code
X-Wa
X-CDN-Cache-Status
XM
NtCoent-Length
SID
Cmsid
Server-ID
X-DynaTrace-JS-Agent
X-Nc
X-Srv
X-API-Version
X-Cdn-Diag
X-Origin-Expires
X-Cache-Backend
CPC-Cache
X-Vmg-Version
CPC-Age
X-TX-ID
X-Nananana
CloudFront-Viewer-Country
X-TIME
X-Lagoon
X-Akamai-Transformed
X-Fpc
X-Via-Fastly
X-LAGOON
X-Api-Version
CacheControlHeader
X-NewRelic-App-Data
X-B3-Parentspanid
X-Hit
X-Zone
X-Nf-Request-Id
User-Agent
Resin-Trace
XkeyRZ
X-Variation
Uri
Cross-Origin-Opener-Policy-Report-Only
X-Proxy-CacheRZ
X-Client-Ip
X-UA
X-Presslabs-Stats
X-CACHE-AGE
X-URL
MIME-Version
X-Datacenter
True-Client-Ip
X-Amz-Meta-Opti
X-Fastly-Country-Code
X-Info
X-LiteSpeed-Tag
Tcn
X-Geo
X-Location
Lb
GeoIP-Latitude
VNS-Age
X-Ig-Origin-Region
X-B3-Spanid
Cache-Hits
VNS-Cache
X-LiteSpeed-Cache-Control
X-HostName
DataCenter
X-Dynatrace-Js-Agent
Fusion-Deployment-Id
Fusion-Source
True-Client-IP
Fusion-Template-Id
Fusion-Content-Id
X-NWS-UUID-VERIFY
X-DataCenter
Cache-Name
X-Vc
Fusion-Component-Id
Fusion-Content-Source
Mime-Version
X-AIR-PT
Hostname
Powered-By
Fastly-Drupal-Html
X-Jungle-Id
X-CUA
X-Dispatcher-Number
X-Cached-By
X-Cloudmap
X-HOST
X-CSRF-TOKEN
Origin-CC
Cf-Ipcountry
Origin-EX
X-CS
X-IAuth-Set-Uid
X-User
X-RID
X-Webkit-Csp-Report-Only
X-Cdn-Forward
X-Mid
Debug
X-Segment-20210421
Srv
X-MCACHE
X-Render-Time
Cl-Cache
X-Wormhole-Sdk
Load-Balancing
X-ECache
X-Varnish-Beresp-TTL
X-VTEX-Cache-Time
X-Esi
BehaviorPad-Version
X-VTEX-Cache-Server
Ohc-File-Size
X-Powered-By-VTEX-Cache
GeoIP-Country-Code
X-Dispatch
X-Litespeed-Tag
CDN
X-Cs
X-WA
X-Auth-Group-Type
Edge-Cache
X-Cdn-Cache-Status
X-FPC
X-Oracle-DMS-ECID
X-NC
Ohc-Cache-HIT
X-ServedByHost
X-Cache-Enabled
X-Lb-Id
Server-Id
YJS-ID
My-App
X-Fastly-Backend-Reqs
CountryCode
X-Wp-Cf-Super-Cache
X-Ig-Push-State
X-Wp-Cf-Super-Cache-Cache-Control
Location
X-NodeID
Server-Info
Rtss
X-Lb-Nocache
X-VCL-Version
Wpo-Cache-Message
Wpo-Cache-Status
X-Litespeed-Cache-Control
Ms-Author-Via
Xkeylog
Xkey-La3
X-Akamai-Pragma-Client-IP
Odigeo-Trace-Id
X-MiniProfiler-Ids
CF-Cached-On
X-Cdn-Request-ID
X-Snapshot-Date
X-Proxy-Cache-La3
CF-Ctrl
X-MSEdge-Flight
X-Internal-Host
X-MSEdge-Features
Section-Origin-Responded
X-Acquia-Site
OriginIP
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Memcached
Memory
X-FL-QIT-DEBUG
Time
Section-Io-Origin-Status
X-FL-EDGE
X-Acquia-Application-Trace
Section-Io-Origin-Time-Seconds
FSS-Cache
Srvid
X-Custom-Header
X-APP-VERSION
Ngx
X-Nitro-Cache
X-Vgn-Hpd-Reason
Geoip-Latitude
X-Nitro-Rev
X-Nitro-Cache-From
X-App
X-Sorting-Hat-Shopid
X-Shardid
X-Cache-Version
X-Shopid
X-Sorting-Hat-Podid
X-PHP-Backend
Akamai-Cache-Status
X-Mg-Cache
X-Dw-Trace-Id
X-Via-PopV
X-Lsadc-Cache
X-Fastly-Cache-Hits
X-Sucuri-Id
X-Th-Server
X-Te-Duration-Ms
X-Te-Count
X-Http-Count
X-Http-Duration-Ms
X-Cache-FS-Status
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-RequestId
X-Check-Cacheable
X-Serial
X-Service-Response-Time
X-Web-Server
Sm-Log-Id
X-Pad
X-Udemy-Cache-App-Namespace
X-Via-PopN
X-Via-PopH
X-Ha-Backend