Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
Accept-CH
P3p
X-Drupal-Cache
X-DNS-Prefetch-Control
X-Cache-Status
Accept-CH-Lifetime
X-Ua-Compatible
X-Generator
X-Check
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
X-Request-ID
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Cf-Edge-Cache
X-Backend
X-UA-Device
Keep-Alive
Request-Context
X-Robots-Tag
Allow
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
EagleId
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
X-Dispatcher
X-Amz-Version-Id
X-Server-Powered-By
X-Dns-Prefetch-Control
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
X-Page-Speed
Ali-Swift-Global-Savetime
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-LiteSpeed-Cache
Cf-Railgun
Permissions-Policy
EagleEye-TraceId
X-WebKit-CSP
X-Backend-Server
X-CST
X-Aws-Lambda-Call-Status
X-OneAgent-JS-Injection
X-Server-Id
X-Host
X-Readtime
X-Cache-Lookup
X-Response-Time
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
X-Litespeed-Cache
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Country
X-Oneagent-Js-Injection
Service-Worker-Allowed
X-Trace
X-Url
X-Content-Type
X-Clacks-Overhead
X-Ruxit-JS-Agent
Accept-Ch-Lifetime
Rating
X-Rack-Cache
Cache-Tag
X-Origin-Cache-Key
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Edge
X-FTR-Request-ID
X-Midtier
Nginx-Cache
X-PC
X-Vname
X-TtlSet
X-Mcache
X-MS-InvokeApp
X-Mod-Pagespeed
X-Upstream
X-ECACHE
X-Powered-By-Plesk
X-Server-Name
X-NWS-LOG-UUID
X-Ruxit-Js-Agent
Edge-Control
X-ESI
X-Times
X-Browser-Type
X-Cnection
X-D2id
X-Element-Page-Cache
Verso
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
X-Exp-Variant
X-Cdn-Fetch
X-Ser
AR-ATIME
AR-SID
AR-PoweredBy
AR-Request-ID
X-Ac
SPRequestDuration
SPIisLatency
X-RateLimit-Remaining
X-SharePointHealthScore
SPRequestGuid
X-B3-TraceId
X-Ttl
X-GitHub-Request-Id
X-Abt-Application-Version
X-NF-Request-ID
X-Navigation-Version
X-Dw-Request-Base-Id
X-Vcap-Request-Id
AR-CACHE
Display
Pagespeed
X-Middleton-Display
X-Sol
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Mg-S
S
X-Client-IP
Edge-Cache-Tag
X-Cache-Key
Fastly-Restarts
X-VARITI-CCR
X-Webkit-Csp
X-Amzn-Trace-Id
X-Cache-TTL
X-Amz-Rid
RTSS
Cache-Status
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Powered-CMS
X-Server-ID
X-Kinsta-Cache
X-Edge-Location-Klb
X-Daa-Tunnel
Access-Control-Request-Method
X-Version
X-Goog-Hash
X-Recruiting
X-Middleton-Response
Response
X-Content-Digest
X-ARC
X-Forwarded-For
X-T
X-TraceId
X-Varnish-TTL
Arr-Disable-Session-Affinity
X-MSEdge-Ref
Cross-Origin-Resource-Policy
Content-MD5
MS-Author-Via
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
MicrosoftSharePointTeamServices
Front-End-Https
X-FastCGI-Cache
X-SRCache-Store-Status
X-Shield-Request-Id
X-SRCache-Fetch-Status
TP-Cache
X-Accel-Expires
X-Cached
Public-Key-Pins
X-Hits
Server-Node
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-Request-Received
X-Ua-Browser
X-HS-Cache-Config
X-Request-Processing-Time
X-Forwarded-Proto
X-Id
X-Frontend
X-Country-Code-Real
X-FTR-Backend
X-FTR-Cache-Status
Payment
X-FTR-Backend-Server
X-FTR-Balancer
X-RateLimit-Limit
Realpath
X-FTR-Expires
X-Content-Security-Policy-Report-Only
X-DIS-Request-ID
X-Protected-By
X-LLID
X-ORACLE-DMS-RID
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Distributor
X-Hostname
TP-L2-Cache
X-GUploader-UploadID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-LB-Cache
Cache-Tags
X-Fastcgi-Cache
Origin-Trial
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
X-Amzn-RequestId
X-Envoy-Decorator-Operation
X-Amz-Apigw-Id
Host
X-Origin-Server
Fastcgi-Cache
Referer-Policy
MRF-Tech
Mrf-Cache-Status
X-ORACLE-DMS-ECID
X-Activity-Id
X-AppVersion
X-Az
X-B3-TraceId-Primal
X-Debug-Info
X-Page-Id
X-NGENIX-Cache
X-Fastly-Request-ID
X-Www-Served-By
X-Cluster-Name
X-Varnish-Backend
X-Varnish-Server
X-XRDS-LOCATION
X-Geo-Country
Accept-Charset
X-Correlation-Id
X-App-Server
X-F-Cache
X-PressLabs-Stats
X-Ezoic-Cdn
Retry-After
X-Varnish-Ttl
X-FB-Debug
X-Px
X-Ratelimit-Limit
TCN
X-Load-Cache
X-Upgrade-Enabled
X-TEC-API-VERSION
X-Goog-Metageneration
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-CSRF-Token
Access-Control-Allow-Method
X-RateLimit-Reset
X-Seen-By
X-ASPNET-VERSION
X-Git-Hash
X-Amz-Meta-S3cmd-Attrs
Server-Name
Cleartype
X-Tt-Trace-Tag
X-Tt-Trace-Host
Section-Io-Cache
X-Revision
X-Contextid
X-Grace
Healthy
X-Trace-Id
X-B
X-Content-Options
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Type
Charset
X-Cache-Control
Paypal-Debug-Id
X-B3-Sampled
X-TT
DC
X-Fb-Rlafr
X-Whom
X-Azure-Ref
X-Request-Guid
X-Air-Pt
X-Proxy
X-Signature
X-B-Cache
X-Wix-Request-Id
X-Mobile
X-App-Environment
X-N
X-Node-Name
Accept-Ch
X-Newrelic-App-Data
X-Oracle-Dms-Ecid
X-Magnolia-Registration
Frame-Options
X-Amz-Replication-Status
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Origin-Cache
Filterid
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-EdgeConnect-Cache-Status
X-Logged-In
X-Time
X-Oracle-Dms-Rid
Content-Disposition
Backend
NGB
X-WebKit-CSP-Report-Only
Viewport
X-Original-Request-Id
X-Response-Served-From
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Akamai-GRN
X-Datadog-Sampled
X-Hl-Ver
MS-CV
Upgrade-Insecure-Requests
Ms-Operation-Id
X-Ratelimit-Remaining
X-Debug-IsConnected
X-Tumblr-Pixel
X-Debug-IsPreview
X-RTag
X-Fastly-Request-Id
X-Tumblr-Pixel-0
X-Unique-Id
X-Tumblr-Pixel-1
X-RemovedCookies
X-Tumblr-User
X-ProcessESI
X-FW-Dynamic
X-FW-Version
X-Debug
X-FW-Type
X-FW-Static
X-FW-Serve
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-FW-Server
Liferay-Portal
X-FW-Hash
X-Is-Bot
X-UUID
X-IPS-LoggedIn
X-Rendered-As
X-Backend-Name
X-Varnish-Grace
X-Servername
SD-X-WS
X-G
X-NYM-Debug-Backend
X-Amzn-Remapped-Content-Length
X-Region
X-Environment-Context
X-Adobe-Loc
X-Instance
X-Cache-Age
X-Adobe-Content
X-L-Path
X-Cacheable-TTL
X-Via-JSL
X-User-Agent
ServerID
X-TTL
X-Proxy-Cache-Info
X-Device-Type
Fastly-SWR
From-Origin
Fastly-SIE
X-Language
X-Cache-Grace
Country
X-Cache-Hit
X-Template
X-VC-Cache
X-Status
X-Rule
Refresh
X-Rid
X-B3-SpanId
Version
X-Ua-Device
X-Webkit-CSP
X-Source
X-INCAP-ABP
X-Providence-Cookie
Countrycode
X-Flags
X-Route-Name
X-Is-Crawler
X-Aspnet-Duration-Ms
Url
X-Storage
GEO-INFO
X-HTML-Minification-Powered-By
X-NODE
SRV
X-Cache-Status-Check
X-App-Version
CDN-RequestId
X-Air-Source
X-Air-Trace-Id
X-Jobs
X-Air-Hostname
WPO-Cache-Status
Alternate-Protocol
X-WP-CF-Super-Cache-Active
WPO-Cache-Message
OT-Force-Account-Verify
X-B3-Traceid
X-Origin-CC
X-Origin-TTL
X-Real-IP
X-Tec-Api-Root
X-Tec-Api-Version
AMP-Access-Control-Allow-Source-Origin
X-Tec-Api-Origin
X-CDN-Forward
X-Content-Powered-By
X-Nginx-Cache
X-Akamai-Request-ID2
X-Cache-Time
X-Rocket-Nginx-Serving-Static
X-ServerID
X-VC
Surrogate-Key
Access-Control-Request-Headers
X-Accel-Version
Amp-Access-Control-Allow-Source-Origin
Protected
X-Mode
X-Cache-Operation
X-Cache-Rule
Webserver
X-Handled-By
X-Akamai-Edgescape
X-Upstream-Ht
Meta-Geo
X-Endurance-Cache-Level
X-Upstream-Ct
Filters
X-Xfnlog-Site
X-Rn-Rsrv
X-UPSTREAM-Address
X-Hosted-By
X-Rewrite-Enabled
Selected-Fe
X-AWS-Id
X-JoinUs
X-LJ-Flow-ID
X-Origin
Cross-Origin-Embedder-Policy
X-Varnish-Cache-Hits
X-Timing-Wait
X-Tumblr-Pixel-2
X-Platform-Router
X-Platform-Processor
X-Edge-Location
X-VWS-Id
X-Served-From
X-SaId
Section-Io-Id
X-Tumblr-Pixel-3
X-Proxy-Build
ServedBy
X-Platform-Cluster
X-Logging-Id
X-Zipkin-Id
X-VCT
X-No-Session
Property-Id
TWC-Privacy
X-Soup
X-Extlb
X-Skip-Cache
CF-IPCountry
X-Restarts
X-Sucuri-Cache
X-Routing-Service
Webcakes-Region
Webcakes-App-Version
X-ProxyCache-Key
X-Lambda-Id
Webcakes-App-Name
TWC-Connection-Speed
X-ProxyCache-Status
TWC-Locale-Group
X-PHP-Host
X-Labrador-Cache-Channel
X-BYPASS-REASON
X-Web-Node
TWC-GeoIP-Country
X-Framework
Node
Mn-Server-Ip
X-Cluster
TWC-Device-Class
X-Director
X-Proxied
X-Worker
TWC-GeoIP-LatLong
X-Origin-Hint
X-Drupal-Cache-Tags
X-Browser-Name
Azure-SiteName
Azure-InstanceId
X-AB
Azure-RegionName
Azure-Version
X-Format
X-Fetched-On
X-Cms-Context
X-Geo-Region
Front
Web-Mar-Node
Apigw-Requestid
Azure-SlotName
X-Say-Cacheable
X-GeoCountry
X-Tcp-Rtt
X-GeoCode
X-RCS-CacheZone
X-Drupal-Cache-Contexts
X-Say-TTL
X-SayCDN-TTL
X-Vercel-Cache
X-Webstats-RespID
X-Varnish-Beresp-Grace
X-Varnish-Age
X-Vercel-Id
X-Redis-Cache
X-Is-Desktop
X-Adobe-Source
X-Is-Mobile
X-S
X-IPLB-Request-ID
X-Is-Tablet
Xet-Cookie
X-IPLB-Instance
X-Locale
X-Is-Supported-Browser
X-Site-Version
X-Reqid
X-R9-Blue-Green-Version
X-Storefront-Renderer-Rendered
X-Tncms
X-Cache-Host
X-Detected-As
X-Forwarded-Host
X-Loop
X-Frame-Option
X-Generation-Time
X-RM-Cache-TTL
X-Cache-Server
X-Tb
X-Cache-Debug
X-Shopify-Stage
X-Httpd
Xserver
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-CachedAt
CDN-Cache
X-Page-View
X-Sucuri-ID
X-TT-LOGID
CDN-Uid
CDN-RequestPullSuccess
X-Use-Mantle
X-Alternate-Cache-Key
X-Origin-Date
Atl-Traceid
X-Git-Commit
Accept-Language
X-Ms-Version
X-Ms-Request-Id
X-Container-Uri
X-Vcache
DB-Nickname
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-Cdn-Origin
WP-Super-Cache
X-Server-W
X-Provided-By
X-XRDS-Location
X-MP-GENERATED-AT
X-Uri
Fastcgi-Useragent
X-Kinja-CCPA
Cross-Origin-Embedder-Policy-Report-Only
X-Vcl-Version
Source
Cache-Tv-Group
Thinkindot-CacheControl
Cross-Origin-Window-Policy
Sid
Thinkindot-CacheControl-Type
TDXMobile
X-CMSURLCustom
X-Thinkindot-L3
X-RID
Thinkindot-Control
X-Shield-Cache-Expires
X-Generated-By
X-Scope-Id
X-Pass-Why
X-Http-Reason
X-Azure-Ref-OriginShield
Content-Secure-Policy
X-FB-TRIP-ID
X-Buckets
X-LSADC-Cache
Cache
Onion-Location
X-DynaTrace
X-SRV
Priority
X-Content-Age
HostName
X-Urbn-Context-Path
X-Optimistic-Header
X-Urbn-Site-Id
Locale
X-DataDome
X-Xrds-Location
X-UA
X-Sql-Duration-Ms
X-Sql-Count
X-Dc
X-WP-CF-Super-Cache-Cookies-Bypass
X-GEO
X-Varnish-Beresp-Ttl
X-Proxy-Cache-Status
X-Lagoon
X-Cluster-Node
X-Request-URI
X-Dispatcher-Server
Candidate-Md5Url
X-Instance-Name
X-Ec-Fail
C-Via
X-External-Request-Id
X-Epic-Correlation-Id
X-Ec-GeoHdr
Vix-Hermes-Req-Id
X-Cache-Bucket
X-Bc-Bl
X-BCube-Filmed-By
X-A-Dcw
X-Bl-Debug
X-A-Dgt
X-B-Cookie
X-Aed
X-A-Wwc
X-Application
T-Server
X-A-Dam
X-A
X-D
X-Destination
X-Connection-Hash
X-Conf
X-Cache-NE
X-A-Ccd
A
X-Developer
Server-Host
Yak-Timeinfo
X-SB
X-Scheme
Origin
Expiry
X-ScT
X-Datadome
X-S-Cookie
Surrogated-Key
DCR-Decision-By
DCR-Processing-Time-Ms
DSUID
X-Rojux
X-SRCache-Key
Ngx.Var.Host
X-Vdms-Path
X-Vtex-Remote-Cache
X-Vdms-Version
Lang
X-Viewer-Country
Magicmarker
X-Varnish-Hostname
Meta-Geo-Continent
Ngx-Var-Key
Gannett-Cam-Experience-Id
X-TIM-N
MD5-Digest
Origin-Agent-Cluster
X-Request-Start
Req-ID
Rendered-Blocks
Sslversion
X-TA-CDN-Provider
X-ND-Cache
X-Correlation-ID
X-PAYTM-SRV-ID
X-Op-Id-All
X-Platform
Redirect-Candidate
Release
WZWS-RAY
X-Newrelic-Synthetics
LB
User-Cache-Control
Ssr
Locid
X-Acquia-Purge-Cdn-Unconfigured
Sever-Int
Tube-Get-Contents
X-Access
Server-Hostname
Server-Ext
On-Server
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
NM-Fastcgi-Cache
Req-Svc-Chain
Tube-Got-Results
Tube-Return
V-Age
Tube-Got-Eval
X-Esi-Check
X-Proxied-Request
X-Pool
X-Pubstack
X-Req
X-Request-Time
X-Origin-Time
X-Nyt-Route
X-NCache
X-Nginx-Cache-Key
X-NMSegId
X-Node-Id
X-Rocket-Build-Number
XM
X-Varnish-Beresp-Status
X-We-Are-Hiring
X-Varnishpool
X-WA-Info
X-VG-TLSProxy
X-Thanos
X-SVT-ORM-VERSION
X-Section
X-Sigma
X-Sigma-Backend
X-SVT-ORM-RULES
X-Moov-Xdn-Version
X-Moov-T
X-Clientip
X-Cache-TTL-Remaining
X-Core-Value
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Cache-Id
X-Cache-Date
X-Amz-Storage-Class
X-Auto-Login
X-B3-Trace-ID
X-Bip
X-Zen-Fury
X-Ec-Custom-Error
X-Level-Front-Cache
L
X-Mly-Id
X-Loc
X-UA-Device-Type
X-Gzip
X-Gdpr
X-Generated-On
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Amz-Meta-Cb-Modifiedtime
X-BBC-Edge-Cache-Status
Click-Count-Error
Cluster
X-Cache-Action
Environment
Click-Count-Action-Start
CDCHOST
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Fastly-GeoIP-CountryCode
Apple-News-Services-Request-Url
Host-ID
X-Cache-Expired-At
X-Service
Fastly-Drupal-HTML
X-Origin-Response-Time
True-Client-Country-4JS
X-Ad-Load-Variation
X-RateLimit-Remaining-Second
Platform
Is-Eu
Producers
X-Contensis-Viewer-Groups
We-Hiring
X-RateLimit-Limit-Second
X-Device-Os
X-Micro-Cache
X-Forwarded-Site
X-Cache-Aspx
X-Aicache-OS
X-AK-Request-ID
Cdnsip
X-TH-Server
X-Cache-Info
X-VG-WebCache
X-VarnishDD-TTL
X-V-Cache
X-Cdn-Srv
X-Var-Ttl
X-Cache-Backend
X-Server-IP
Cdncip
X-Fastly-Cache
X-ApacheServer
Adler-Geo
X-Region-Sid
X-Block-Status
X-SD-PageType
X-DPWN-IS-SECURE
X-From
Content-Script-Type
Content-Style-Type
Country-Code
X-Varnish-Director
RNT-Machine
Mail-Subject
RNT-Time
X-Hnp-Log
Pramga
X-Human
X-VServer
Esi-Enabled
Fastly-SSL
PFcat
X-Varnish-Authentication
Gh-Request-Id
X-HN
X-Gen-Mode
X-Men
X-Geo-Header
X-GeoIP
Canary
X-PERF
X-Org
Machine
X-GoCache-CacheStatus
X-ECache
Uber-Trace-Id
X-GeoIP-City
X-Test
X-Proto
X-Via-Edge
X-Via-CDN
X-CGP
X-Up
X-Old-Content-Length
X-Via-SSL
X-Eu-Site
X-FC-Vary-Parameters
X-Fmm-Version
X-Hash
X-Request-Host
X-Edge-Server
X-HS-Content-Campaign-Id
X-Policy
X-VCache
X-Csrf-Jwt
X-Wikidot-Static-Cache
W
Web-Mar-Region
Cache-Key
Cache-Provider
X-Origin-Expires
AKAMAI
X-Wikidot-Backend
X-API-Version
Edge-Copy-Time
X-Backend-Instance
X-Mvc-Supplant-Cachable
Cdn-Host
Cdn-Request-Time
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
Proxy-Firewall
NGX
X-Branch-Name
Cf-Device-Type
X-Sn-Servicetimems
S-Rt
Cache-Hits
X-Accel-Expires-Debug
X-LB-ID
Fastly-Backend-Name
X-Mvc-Supplant-OutputCached
X-App-Name
X-Parent-Response-Time
X-Slack-Shared-Secret-Outcome
X-Mg-Request-UUID
X-Date
X-Slack-Backend
X-Ah-Environment
X-CacheTTL
X-Fastly-Backend
X-Tx-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Hits
X-Servedbyhost
X-COUNTRY
X-Zone
Type
X-DC
X-PDP-UNCACHING-HASH
X-Via-Poph
X-DynaTrace-JS-Agent
X-Via-Fastly
X-HA-Backend
X-Ua
X-Via-Popv
NtCoent-Length
X-Via-Popn
Pics-Label
X-CACHE-GROUP
X-NGINX-Cache
X-Ratelimit-Reset
Cdn
X-Srv
X-Refresh
X-NWS-UUID-VERIFY
X-Cloudmap
X-VHOST
X-TimeS
Datacenter
X-Irp-Debug
X-LB-NoCache
X-Location
X-Ig-Origin-Region
Cdn-Requestid
X-Owner
Fusion-Content-Id
Fusion-Template-Id
X-CDN-Cache-Status
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Deployment-Id
GeoIp-Country-Code
X-Esi
X-Core-Mission
IsBot
X-SIPLIST1
Server-ID
Resin-Trace
X-Nc
SID
Powered-By
X-Wa
X-ZONE
X-Akamai-Transformed
X-Fpc
X-Jungle-Id
Origin-CC
Cross-Origin-Opener-Policy-Report-Only
Origin-EX
X-TX-ID
X-Hit
X-Nananana
DataCenter
X-CUA
GeoIP-Latitude
X-Qloud-Router
X-Wormhole-Sdk
X-User
N-Cache
X-CF-Lambda-Version
CloudFront-Viewer-Country
Expect-Staple
X-CF-Lambda-Fn
X-Proxy-CacheRZ
XkeyRZ
X-Nf-Request-Id
X-B3-Parentspanid
X-NewRelic-App-Data
X-Tt-Logid
X-Client-Ip
Xc-Version
X-URL
X-Orig-Expires
X-Presslabs-Stats
Uri
X-CS
X-Render-Time
X-Shop-Environment
X-Segment-20210421
X-Cache-Type
X-IAuth-Set-Uid
X-Tenant
X-DataCenter
X-Forwarded-Path
Mime-Version
X-Amz-Meta-Opti
Debug
True-Client-Ip
X-Gamma-Serve
Cmsid
X-TIME
Cmstype
X-Cached-By
X-LiteSpeed-Tag
User-Agent
Fastly-Drupal-Html
CPC-Age
CPC-Cache
X-VTEX-Cache-Server
X-Auth-Group-Type
Edge-Cache
X-VTEX-Cache-Time
X-Powered-By-VTEX-Cache
Cf-Ipcountry
True-Client-IP
X-Fastly-Country-Code
X-Cdn-Diag
MIME-Version
X-Info
X-CACHE-AGE
X-Vmg-Version
X-Geo
X-Dynatrace-Js-Agent
X-Cs
X-Dispatch
X-Varnish-Beresp-TTL
Load-Balancing
X-Ig-Push-State
X-LiteSpeed-Cache-Control
CDN
X-B3-Spanid
Odigeo-Trace-Id
Srv
X-Datacenter
X-HOST
X-Vc
CacheControlHeader
X-Variation
X-PHP-Backend
X-Custom-Header
X-NodeID
Ohc-File-Size
X-LAGOON
X-Webkit-Csp-Report-Only
X-Cdn-Forward
X-CSRF-TOKEN
X-Depends
Cl-Cache
Hostname
X-Vgn-Hpd-Reason
Tcn
X-APP-VERSION
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-MCACHE
X-Pad
X-DefElseHash
X-DefHash
X-FPC
Server-Id
Ohc-Cache-HIT
X-AIR-PT
X-M-Reqid
X-VC-TTL
X-HostName
X-Lb-Nocache
GeoIP-Country-Code
VNS-Cache
X-WA
X-M-Log
VNS-Age
X-NC
X-Oracle-DMS-ECID
X-Cdn-Cache-Status
Epwk-X-Cache
X-Cache-FS-Status
Geoip-Latitude
X-Api-Version
X-Cache-Ttl
X-MSEdge-Features
PICS-Label
X-Via-PopV
X-Via-PopH
X-MSEdge-Flight
X-Ha-Backend
X-Fastly-Backend-Reqs
X-Via-PopN
CountryCode
X-APP
X-ServedByHost
Cloudfront-Viewer-Country
X-Dispatcher-Number
X-Litespeed-Tag
X-VCL-Version
X-Srcache-Fetch-Status
X-Litespeed-Cache-Control
X-Srcache-Store-Status
Xkeylog
Xkey-La3
X-Cdn-Request-ID
X-Proxy-Cache-La3
X-Lb-Id
Ngx
FSS-Cache
Lb
X-MiniProfiler-Ids
Server-Info
X-Th-Server
X-Acquia-Application-Trace
X-RequestId
X-Acquia-Purge-Tags
X-Acquia-Site
Time
X-Check-Cacheable
X-Web-Server
Memcached
Memory
X-Serial
X-Akamai-Pragma-Client-IP
X-Acquia-Application-UUID
X-IN-APIGATEWAY
OriginIP
X-IN-APIGATEWAYSSL
X-Mid
X-Shopid
X-Shardid
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Cache-Version
X-RAMCache
Akamai-Cache-Status
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Ramcache
BehaviorPad-Version
X-Service-Response-Time
X-FL-QIT-DEBUG
Srvid
Serverhost
X-Udemy-Cache-App-Namespace
Cache-Name
Sm-Log-Id
X-Snapshot-Date
Warning
X-Mg-Cache
X-Sucuri-Id
X-Dw-Trace-Id
X-Requestid