Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
X-Drupal-Cache
X-Cache-Status
Accept-CH-Lifetime
X-DNS-Prefetch-Control
P3p
X-Generator
X-Check
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
X-Request-ID
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Cf-Edge-Cache
X-Backend
X-UA-Device
Keep-Alive
Request-Context
X-Robots-Tag
X-Server
X-Cache-Group
Allow
EagleId
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
X-Rq
X-Dns-Prefetch-Control
X-Vhost
X-Amz-Version-Id
X-Dispatcher
X-Server-Powered-By
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-Pingback
Permissions-Policy
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Cf-Railgun
EagleEye-TraceId
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Backend-Server
X-Cache-Lookup
X-CST
X-Host
X-Server-Id
X-Readtime
X-Aws-Lambda-Call-Status
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Litespeed-Cache
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
Content-Location
X-Country-Code
X-Country
X-Ruxit-JS-Agent
Service-Worker-Allowed
X-Trace
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
Rating
Cache-Tag
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
Cross-Origin-Opener-Policy
X-TtlSet
Nginx-Cache
X-PC
X-Vname
X-Mcache
X-Edge
X-NWS-LOG-UUID
X-Midtier
X-Times
X-MS-InvokeApp
X-Origin-Cache-Key
X-Upstream
X-Mod-Pagespeed
X-Server-Name
X-Powered-By-Plesk
X-Browser-Type
Edge-Control
X-ECACHE
X-ESI
X-Cnection
X-D2id
X-Element-Page-Cache
X-Kinja
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Id
X-GoogleNews-Bot
Verso
X-Ser
AR-ATIME
AR-SID
AR-Request-ID
AR-PoweredBy
X-Ac
X-RateLimit-Remaining
SPIisLatency
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
X-GitHub-Request-Id
X-Ruxit-Js-Agent
X-B3-TraceId
X-NF-Request-ID
X-Abt-Application-Version
X-Navigation-Version
X-Vcap-Request-Id
X-Dw-Request-Base-Id
AR-CACHE
X-Ttl
X-Mg-S
X-Client-IP
X-Middleton-Display
Display
Pagespeed
X-Sol
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
S
Edge-Cache-Tag
X-Webkit-Csp
X-Daa-Tunnel
X-Cache-Key
Fastly-Restarts
X-Cache-TTL
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-VARITI-CCR
X-Amz-Rid
X-Amzn-Trace-Id
Cache-Status
X-Powered-CMS
RTSS
X-Kinsta-Cache
X-Edge-Location-Klb
X-Version
Access-Control-Request-Method
X-Goog-Hash
X-Varnish-TTL
X-Middleton-Response
Response
X-Server-ID
X-Recruiting
X-FastCGI-Cache
X-Content-Digest
X-TraceId
X-ARC
X-Forwarded-For
X-T
X-MSEdge-Ref
Arr-Disable-Session-Affinity
Cross-Origin-Resource-Policy
MS-Author-Via
MicrosoftSharePointTeamServices
Front-End-Https
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
TP-Cache
X-Shield-Request-Id
X-FTR-Balancer
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend
X-Accel-Expires
X-Id
X-Cached
X-Forwarded-Proto
X-Hits
X-Request-Received
X-Ua-Browser
X-Request-Processing-Time
Realpath
X-FTR-Expires
Public-Key-Pins
Server-Node
X-ORACLE-DMS-RID
X-HS-Hub-Id
X-HS-Content-Id
Payment
X-Frontend
X-HS-Combine-CSS
X-HS-Cache-Config
X-Protected-By
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-RateLimit-Limit
X-LLID
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Content-Security-Policy-Report-Only
X-Distributor
X-DIS-Request-ID
X-Fastly-Request-ID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Correlation-Id
X-GUploader-UploadID
X-ORACLE-DMS-ECID
X-LB-Cache
X-XRDS-LOCATION
TP-L2-Cache
Cache-Tags
X-Request-Handler-Origin-Region
X-Microsite
Fastcgi-Cache
Count-Hit
Referer-Policy
X-Amz-Apigw-Id
X-Amzn-RequestId
MRF-Tech
Host
Mrf-Cache-Status
X-B3-TraceId-Primal
X-AppVersion
X-Activity-Id
X-Debug-Info
X-Envoy-Decorator-Operation
X-Cluster-Name
X-Hostname
X-NGENIX-Cache
X-Az
X-Www-Served-By
X-Origin-Server
X-Varnish-Backend
X-Geo-Country
X-Varnish-Server
X-Page-Id
Accept-Charset
X-App-Server
X-Ezoic-Cdn
X-PressLabs-Stats
X-Ratelimit-Limit
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-F-Cache
Retry-After
X-Px
X-Load-Cache
X-RateLimit-Reset
X-Goog-Metageneration
Origin-Trial
X-FB-Debug
X-Upgrade-Enabled
X-CSRF-Token
X-Seen-By
Server-Name
TCN
X-Amz-Meta-S3cmd-Attrs
Cleartype
Access-Control-Allow-Method
X-Git-Hash
X-Fastcgi-Cache
X-Request-Guid
X-Tt-Trace-Host
X-Tt-Trace-Tag
Section-Io-Cache
X-Grace
X-Cache-Control
X-Revision
X-B3-Sampled
X-Contextid
X-TT
X-Azure-Ref
X-Trace-Id
Healthy
X-Type
X-Webkit-CSP
X-B
Paypal-Debug-Id
Charset
X-Whom
DC
X-Fb-Rlafr
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Proxy
X-Content-Options
X-Wix-Request-Id
X-Mobile
X-N
X-Newrelic-App-Data
X-Signature
X-B-Cache
X-App-Environment
X-Node-Name
X-TTL
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Varnish-Ttl
X-CCDN-Origin-Time
X-Magnolia-Registration
X-Air-Pt
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Accept-Ch
Filterid
X-Amz-Replication-Status
X-Origin-Cache
X-Oracle-Dms-Ecid
Frame-Options
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Time
X-Logged-In
X-EdgeConnect-Cache-Status
Viewport
X-Unique-Id
NGB
VIX-Pulpo-Upstream-Status
X-Debug
X-Cache-Grace
X-Oracle-Dms-Rid
VIX-Pulpo-Node
X-Debug-IsConnected
X-Is-Bot
X-ProcessESI
Backend
X-Tumblr-Pixel-1
X-Rendered-As
X-Tumblr-Pixel
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Debug-IsPreview
X-Tumblr-Pixel-0
X-Tumblr-User
X-RemovedCookies
X-Adobe-Loc
X-Adobe-Content
Fastly-SWR
X-Servername
SD-X-WS
X-Varnish-Grace
X-G
Liferay-Portal
Fastly-SIE
X-Datadog-Sampled
Content-Disposition
X-Amzn-Remapped-Content-Length
X-NYM-Debug-Backend
X-IPS-LoggedIn
X-RTag
X-Instance
X-FW-Version
X-Cache-Age
X-FW-Serve
MS-CV
X-WebKit-CSP-Report-Only
X-FW-Type
X-FW-Static
X-FW-Hash
X-FW-Dynamic
X-FW-Server
X-Backend-Name
Ms-Operation-Id
X-UUID
X-Hl-Ver
ServerID
X-Cacheable-TTL
X-VC-Cache
X-Original-Request-Id
X-Response-Served-From
From-Origin
X-L-Path
X-Via-JSL
X-Environment-Context
X-Proxy-Cache-Info
X-Device-Type
X-Region
X-User-Agent
X-Ratelimit-Remaining
Version
Akamai-GRN
Upgrade-Insecure-Requests
X-Rule
X-Cache-Hit
X-Status
X-Ua-Device
Country
X-B3-SpanId
X-Source
Refresh
X-Template
X-INCAP-ABP
GEO-INFO
Countrycode
X-Fastly-Request-Id
CDN-RequestId
X-Storage
X-Language
Url
OT-Force-Account-Verify
X-Rid
X-HTML-Minification-Powered-By
SRV
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-Cache-Status-Check
X-WP-CF-Super-Cache-Active
X-NODE
X-Real-IP
Alternate-Protocol
AMP-Access-Control-Allow-Source-Origin
X-ServerID
WPO-Cache-Message
WPO-Cache-Status
X-Origin-TTL
X-Origin-CC
X-B3-Traceid
X-Jobs
X-Akamai-Request-ID2
X-App-Version
Surrogate-Key
X-CDN-Forward
X-Sucuri-Cache
X-Flags
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
X-VC
X-Route-Name
X-Content-Powered-By
Access-Control-Request-Headers
X-Cache-Time
Protected
X-Sucuri-ID
X-Mode
X-Rocket-Nginx-Serving-Static
X-Handled-By
X-Accel-Version
Amp-Access-Control-Allow-Source-Origin
Xet-Cookie
X-Upstream-Ct
X-UPSTREAM-Address
X-Upstream-Ht
X-Rn-Rsrv
X-Endurance-Cache-Level
Webserver
Filters
Meta-Geo
X-Rewrite-Enabled
X-Akamai-Edgescape
X-TT-LOGID
X-Hosted-By
ServedBy
Selected-Fe
X-Adobe-Source
Section-Io-Id
Cross-Origin-Embedder-Policy
X-Cache-Operation
X-Cache-Rule
Front
X-RM-Cache-TTL
X-Cache-Debug
X-Edge-Location
X-Tumblr-Pixel-3
X-Webstats-RespID
X-Worker
X-Xfnlog-Site
X-Tumblr-Pixel-2
X-Timing-Wait
X-JoinUs
X-Origin
X-SaId
X-Detected-As
X-Proxy-Build
X-Nginx-Cache
X-Cms-Context
X-Director
X-AWS-Id
Webcakes-Region
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Origin-Hint
X-Logging-Id
X-Labrador-Cache-Channel
X-Extlb
Webcakes-App-Version
Atl-Traceid
TWC-Connection-Speed
TWC-Device-Class
Property-Id
Node
Mn-Server-Ip
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-App-Name
Web-Mar-Node
TWC-Privacy
TWC-Locale-Group
X-PHP-Host
X-LJ-Flow-ID
X-Varnish-Cache-Hits
X-Routing-Service
X-Redis-Cache
X-Soup
X-Served-From
X-VWS-Id
X-Framework
X-Zipkin-Id
X-Proxied
X-Web-Node
X-Browser-Name
X-Site-Version
X-Skip-Cache
X-AB
X-Tncms
Xserver
CDN-Uid
X-VCT
X-Varnish-Age
X-Tcp-Rtt
X-SayCDN-TTL
X-Tb
X-Say-TTL
X-Locale
CDN-RequestPullSuccess
X-Lambda-Id
X-ProxyCache-Status
X-Loop
X-ProxyCache-Key
X-Origin-Date
X-No-Session
X-RCS-CacheZone
X-Is-Tablet
X-Restarts
X-Say-Cacheable
X-Cluster
X-Forwarded-Host
X-Geo-Region
X-Is-Supported-Browser
X-Is-Mobile
X-Is-Desktop
X-BYPASS-REASON
X-S
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDN-PullZone
X-RID
CDN-RequestPullCode
CDN-RequestCountryCode
X-Tec-Api-Root
X-Tec-Api-Origin
X-Cache-Host
X-Alternate-Cache-Key
Apigw-Requestid
X-Fetched-On
Azure-RegionName
Azure-InstanceId
X-Format
X-Cdn-Origin
X-Container-Uri
X-Git-Commit
X-GeoCountry
X-Httpd
X-IPLB-Instance
X-Generation-Time
Azure-SlotName
X-IPLB-Request-ID
X-GeoCode
Azure-SiteName
X-Storefront-Renderer-Rendered
X-Shopify-Stage
Azure-Version
X-Vercel-Cache
X-Varnish-Beresp-Grace
X-Tec-Api-Version
X-Vercel-Id
X-R9-Blue-Green-Version
X-Ms-Request-Id
Accept-Language
X-Ms-Version
X-Platform-Processor
X-Provided-By
X-Vcache
X-Platform-Cluster
X-Reqid
X-Platform-Router
X-Frame-Option
Fastcgi-Useragent
X-Sorting-Hat-PodId
X-ShopId
X-Sorting-Hat-ShopId
X-Cache-Server
X-ShardId
DB-Nickname
Cross-Origin-Window-Policy
X-XRDS-Location
X-SRV
X-Server-W
X-Vcl-Version
X-Azure-Ref-OriginShield
Source
WP-Super-Cache
CF-IPCountry
X-MP-GENERATED-AT
X-PDP-UNCACHING-HASH
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Scope-Id
X-Thinkindot-L3
Sid
X-Shield-Cache-Expires
X-CMSURLCustom
Thinkindot-Control
TDXMobile
X-Generated-By
Cross-Origin-Embedder-Policy-Report-Only
X-Page-View
Cache
X-Uri
X-UA
X-Pass-Why
Cache-Tv-Group
X-FB-TRIP-ID
X-Buckets
Content-Secure-Policy
X-Optimistic-Header
X-Lagoon
X-DataDome
HostName
X-LSADC-Cache
X-ECache
Onion-Location
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Dc
X-Content-Age
X-WP-CF-Super-Cache-Cookies-Bypass
X-Use-Mantle
Priority
X-Request-URI
X-Http-Reason
X-GEO
X-Xrds-Location
X-Connection-Hash
User-Cache-Control
X-DynaTrace
Expiry
Locid
X-Datadome
X-SRCache-Key
X-Bc-Bl
X-Cache-Bucket
X-TIM-N
X-ND-Cache
X-Conf
X-BCube-Filmed-By
X-Bl-Debug
X-A-Dcw
T-Server
Ngx-Var-Key
Ngx.Var.Host
Meta-Geo-Continent
MD5-Digest
LB
Magicmarker
Surrogated-Key
Origin
Rendered-Blocks
Req-ID
Redirect-Candidate
Server-Host
Origin-Agent-Cluster
Sslversion
Lang
Vix-Hermes-Req-Id
X-A-Wwc
X-A-Dgt
Candidate-Md5Url
X-Aed
A
X-Rojux
X-A-Dam
X-A-Ccd
Gannett-Cam-Experience-Id
X-Platform
DCR-Processing-Time-Ms
DCR-Decision-By
X-A
X-Request-Start
X-ScT
X-Cache-NE
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Developer
X-Vdms-Version
X-Vtex-Remote-Cache
X-Op-Id-All
X-Vdms-Path
X-Ec-Fail
X-Dispatcher-Server
X-Viewer-Country
X-D
X-Varnish-Hostname
X-Cluster-Node
X-NWS-UUID-VERIFY
Cache-Hits
X-Proxy-Cache-Status
X-GeoIP
X-Forwarded-Site
X-AK-Request-ID
X-SB
X-S-Cookie
X-GeoIP-City
C-Via
X-Application
X-B3-Trace-ID
X-Generated-On
X-B-Cookie
X-Varnishpool
X-Auto-Login
NM-Fastcgi-Cache
Cdncip
Environment
DSUID
X-Level-Front-Cache
X-NMSegId
Wxu-Next-Hostname
Wxu-Next-Commit
V-Age
X-NCache
Fastly-SSL
X-Cache-Action
X-Req
Wxu-Next-Region
X-Gdpr
X-Loc
Cdnsip
X-Nyt-Route
Cluster
X-Nginx-Cache-Key
Content-Style-Type
Content-Script-Type
X-Fastly-Cache
True-Client-Country-4JS
X-WA-Info
Server-Hostname
X-TA-CDN-Provider
X-PAYTM-SRV-ID
X-External-Request-Id
X-Cache-TTL-Remaining
X-Varnish-Beresp-Ttl
X-Scheme
X-Cache-Id
Pramga
X-Thanos
XM
X-Core-Value
Server-Ext
X-Pubstack
Release
X-Clientip
X-UA-Device-Type
X-Origin-Time
X-Origin-Expires
Yak-Timeinfo
X-Esi-Check
X-GeoIP-Region-Code
X-Kinja-CCPA
X-Gzip
X-GeoIP-Country-Code
X-SD-PageType
Host-ID
X-Ec-Custom-Error
X-Destination
X-Device-Os
X-Node-Id
Sever-Int
X-Debug-Cache-Fetch
X-Bip
X-Debug-Cache-Store
X-Service
X-Origin-Response-Time
X-Cache-Expired-At
Uber-Trace-Id
Tube-Return
X-Pool
X-Proxied-Request
X-FC-Vary-Parameters
X-Fmm-Version
Tube-Got-Results
Tube-Got-Eval
Ssr
X-Men
X-Micro-Cache
Tube-Get-Contents
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Aspx
X-Cache-Backend
X-Cache-Info
X-Block-Status
X-GoCache-CacheStatus
X-Backend-Instance
X-BBC-Edge-Cache-Status
X-PERF
X-Cdn-Srv
X-Org
X-Hnp-Log
X-Moov-Xdn-Version
X-HS-Content-Campaign-Id
X-Human
X-Contensis-Viewer-Groups
X-Geo-Header
X-ApacheServer
X-DPWN-IS-SECURE
RNT-Time
Web-Mar-Region
We-Hiring
X-Mly-Id
X-From
X-Gen-Mode
X-Access
X-HN
X-Amz-Storage-Class
X-Moov-T
X-Old-Content-Length
X-Acquia-Purge-Cdn-Unconfigured
X-Ad-Load-Variation
X-Policy
X-TH-Server
Apple-News-Services-Host
X-Aicache-OS
Apple-News-Services-Handled
Adler-Geo
X-Server-IP
X-Section
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Click-Count-Error
X-Zen-Fury
Click-Count-Action-Start
CDCHOST
Canary
X-VG-TLSProxy
X-Newrelic-Synthetics
X-Var-Ttl
X-V-Cache
X-Varnish-Authentication
X-Sql-Count
X-Varnish-Beresp-Status
X-Sql-Duration-Ms
X-Varnish-Director
RNT-Machine
X-Sn-Servicetimems
X-VarnishDD-TTL
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-We-Are-Hiring
X-Request-Time
Cache-Provider
Machine
Gh-Request-Id
X-VG-WebCache
PFcat
On-Server
Country-Code
X-Mvc-Supplant-Cachable
X-RateLimit-Remaining-Second
Is-Eu
L
Mail-Subject
Req-Svc-Chain
X-Region-Sid
Esi-Enabled
X-Request-Host
Platform
X-RateLimit-Limit-Second
Fastly-GeoIP-CountryCode
Producers
X-NGINX-Cache
X-Eu-Site
X-Edge-Server
X-Mvc-Supplant-OutputCached
X-Up
X-Csrf-Jwt
Proxy-Firewall
X-CGP
X-Fastly-Backend
X-Wikidot-Backend
X-Instance-Name
X-Test
X-Slack-Backend
X-Wikidot-Static-Cache
Cache-Key
W
Cdn-Host
Cdn-Request-Time
Cf-Device-Type
X-Hash
X-Proto
X-App-Name
X-Slack-Shared-Secret-Outcome
Ha-Gx-Prefs
L5d-Success-Class
HA-Ipaddr
AKAMAI
X-Cloudmap
Fastly-Drupal-HTML
X-Date
X-LB-ID
X-VServer
X-Via-Fastly
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Date
X-Sigma-Backend
Fastly-Backend-Name
X-Rocket-Build-Number
X-Sigma
X-Accel-Expires-Debug
NGX
X-CacheTTL
WZWS-RAY
X-VCache
X-Tx-Id
X-Ah-Environment
X-Mg-Request-UUID
X-Ig-Origin-Region
X-Location
NtCoent-Length
X-Branch-Name
X-DynaTrace-JS-Agent
X-COUNTRY
X-API-Version
X-Parent-Response-Time
X-Zone
X-DC
X-Varnish-Hits
Datacenter
Pics-Label
X-Refresh
X-Via-Poph
X-Via-Popn
Fusion-Component-Id
X-HA-Backend
Fusion-Deployment-Id
X-Via-Popv
Edge-Copy-Time
X-Via-SSL
X-Via-Edge
X-Via-CDN
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
X-CACHE-GROUP
X-Ratelimit-Reset
X-Correlation-ID
S-Rt
X-Wormhole-Sdk
X-CDN-Cache-Status
X-Servedbyhost
GeoIp-Country-Code
Type
X-Akamai-Transformed
X-VHOST
X-CUA
X-Jungle-Id
Powered-By
Cdn
Origin-CC
X-Ua
Origin-EX
Resin-Trace
X-Esi
X-ZONE
X-LB-NoCache
X-User
SID
X-Irp-Debug
Cf-Ipcountry
Cdn-Requestid
Server-ID
X-Srv
X-TX-ID
X-Wa
GeoIP-Latitude
X-Core-Mission
X-Nc
X-Owner
X-SIPLIST1
Cross-Origin-Opener-Policy-Report-Only
X-Powered-By-VTEX-Cache
X-LiteSpeed-Tag
X-VTEX-Cache-Server
X-Hit
IsBot
X-VTEX-Cache-Time
X-Render-Time
X-Cached-By
Fastly-Drupal-Html
X-Nananana
X-CS
X-NewRelic-App-Data
XkeyRZ
CloudFront-Viewer-Country
X-Nf-Request-Id
Uri
X-B3-Parentspanid
X-Fpc
X-Proxy-CacheRZ
X-Qloud-Router
Mime-Version
DataCenter
X-Client-Ip
X-URL
X-Auth-Group-Type
X-IAuth-Set-Uid
X-DataCenter
X-Presslabs-Stats
Edge-Cache
Debug
True-Client-IP
X-Segment-20210421
X-LiteSpeed-Cache-Control
X-TIME
X-Tt-Logid
Expect-Staple
N-Cache
X-Amz-Meta-Opti
X-Cs
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Ig-Push-State
X-AIR-PT
CDN
X-Varnish-Beresp-TTL
X-PHP-Backend
X-Shop-Environment
Xc-Version
X-Orig-Expires
X-Cache-Type
X-Tenant
X-Forwarded-Path
Odigeo-Trace-Id
Srv
X-HostName
X-Vgn-Hpd-Reason
MIME-Version
True-Client-Ip
Cmstype
X-Gamma-Serve
Cmsid
X-Custom-Header
X-Geo
X-CACHE-AGE
X-NodeID
X-Dynatrace-Js-Agent
X-Info
User-Agent
X-Pad
Tcn
CPC-Age
Load-Balancing
X-Vmg-Version
CPC-Cache
X-Dispatch
X-Cdn-Forward
X-Api-Version
X-B3-Spanid
X-Cdn-Diag
X-HOST
X-FPC
X-Fastly-Country-Code
X-NC
X-Varnish-Remaining-TTL
X-WA
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Vc
X-Depends
X-DefHash
X-DefElseHash
Request-ID
X-VC-TTL
Ohc-File-Size
X-M-Reqid
X-M-Log
X-APP-VERSION
X-Webkit-Csp-Report-Only
X-Variation
Cl-Cache
Hostname
X-Datacenter
X-CSRF-TOKEN
Server-Id
X-Lb-Nocache
Geoip-Latitude
X-Cache-FS-Status
X-APP
CacheControlHeader
X-LAGOON
Ohc-Cache-HIT
X-TimeS
GeoIP-Country-Code
X-ServedByHost
X-Cdn-Cache-Status
X-Oracle-DMS-ECID
PICS-Label
X-Ha-Backend
VNS-Age
VNS-Cache
Epwk-X-Cache
Cloudfront-Viewer-Country
FSS-Cache
Server-Info
X-Cache-Ttl
Srvid
X-FL-QIT-DEBUG
X-MSEdge-Features
ServerHost
X-Via-PopN
CountryCode
BehaviorPad-Version
X-Via-PopV
X-Litespeed-Tag
X-Via-PopH
X-MSEdge-Flight
X-Fastly-Backend-Reqs
X-Srcache-Store-Status
Rtss
X-Litespeed-Cache-Control
X-VCL-Version
X-Srcache-Fetch-Status
X-Cdn-Request-ID
Xkeylog
X-Proxy-Cache-La3
X-Lb-Id
Xkey-La3
Time
X-Snapshot-Date
OriginIP
X-Serial
X-IN-APIGATEWAY
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-IN-APIGATEWAYSSL
X-Th-Server
X-MiniProfiler-Ids
X-RequestId
Memcached
Ngx
Memory
X-Web-Server
X-Check-Cacheable
X-Akamai-Pragma-Client-IP
X-Dispatcher-Number
X-Sorting-Hat-Shopid
X-Shopid
X-Shardid
X-Cache-Version
X-Sorting-Hat-Podid
X-Content-Length
X-RAMCache
X-Service-Response-Time
X-Ramcache
X-Dw-Trace-Id
X-Mg-Cache
Sm-Log-Id
X-Udemy-Cache-App-Namespace
X-Wp-Cf-Super-Cache-Cookies-Bypass
Akamai-Cache-Status
Warning
X-Sucuri-Id
X-Requestid